Communication system, first function performing device, and second function performing device

The communication system facilitates secure function execution in a first device by utilizing a second device's key-based authentication, addressing the challenge of integrating function-performing devices through a predetermined authentication scheme.

JP7753688B2Active Publication Date: 2025-10-15BROTHER KOGYO KK
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2021098960
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-06-14
Publication Date
2025-10-15
Estimated Expiration
2041-06-14

AI Technical Summary

Technical Problem

Existing systems lack an efficient method for causing a first function-performing device to perform a function using a second function-performing device through a predetermined authentication scheme utilizing a pair of keys.

Method used

A communication system comprising a first and second function-performing device, where the first device sends a result information request to the second device upon user instruction, and the second device encrypts and decrypts verification information using a pair of keys to authenticate the user, allowing the first device to execute a function upon successful authentication.

Benefits of technology

Enables the first function-performing device to perform its function by leveraging the authentication of the second device, ensuring secure and efficient operation through key-based authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007753688000001
    Figure 0007753688000001
  • Figure 0007753688000002
    Figure 0007753688000002
  • Figure 0007753688000003
    Figure 0007753688000003
Patent Text Reader

Abstract

To provide a technology for making a first function execution device execute a first function by using a second function execution device that operates according to a predetermined authentication method using a pair of keys.SOLUTION: A first function execution device transmits a result information request to a second function execution device when a first function execution instruction is given thereto from a target user. The second function execution device transmits first verification information to a terminal device when receiving an access from the terminal device. When first authentication of the target user is successful, the terminal device generates first signature information by using a secret key and transmits the first signature information to the second function execution device. The second function execution device decrypts the first signature information by using a public key and transmits result information to the first function execution device when successfully obtaining the first verification information and receiving a result information request from the first function execution device. The first function execution device executes a first function when receiving the result information from the second function execution device.SELECTED DRAWING: Figure 5
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] This specification discloses a technique for causing a first function performing device to perform a first function in accordance with a predetermined authentication method that uses a pair of keys. [Background technology]

[0002] Patent Document 1 discloses a system including an image processing device, an external authenticator, and a service providing system. When the image processing device accepts an operation to use a printing service, it transmits a service provision request to the service providing system, receives a biometric authentication request including an Assertion Challenge from the service providing system, and transmits an assertion creation request including the Assertion Challenge to the external authenticator. If the biometric authentication is successful, the external authenticator encrypts the Assertion Challenge using a private key to generate signature data. The external authenticator then transmits assertion information including the signature data to the image processing device, and the image processing device transmits an assertion verification request including the assertion information to the service providing system. The service providing system decrypts the signature data included in the assertion information using a public key, and if the decrypted value matches the Assertion Challenge, determines that user authentication is successful and transmits a signal to the image processing device to provide the printing service. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Publication No. 2019-86937 Summary of the Invention [Problem to be solved by the invention]

[0004] This specification provides a novel technique for causing a first function-performing device to perform a first function using a second function-performing device that operates according to a predetermined authentication scheme that utilizes a pair of keys. [Means for solving the problem]

[0005] The communication system disclosed in this specification may include a first function-performing device and a second function-performing device different from the first function-performing device, the second function-performing device being operable according to a predetermined authentication scheme utilizing a pair of keys. the first function performing device comprises a result information request sending unit that, when a first function performing instruction is given from a target user to the first function performing device, sends a result information request to the second function performing device, requesting the transmission of result information indicating that authentication of the target user has been successful; and the second function performing device comprises a first verification information sending unit that, in response to the first function performing instruction being given to the first function performing device, sends first verification information to the terminal device when accepting access to the second function performing device from a terminal device operable according to the predetermined authentication method, the terminal device receives the first verification information from the second function performing device, and, when first authentication of the target user performed by the terminal device is successful, encrypts the first verification information using a private key of the pair of keys to generate first signature information and sends the first signature information to the second function performing device; and a first decryption unit that decrypts the first signature information by using a public key of the pair of keys when the first signature information is received from the terminal device in response to the first function performing device being authenticated; a result information request receiving unit that receives the result information request from the first function performing device; and a result information sending unit that sends the result information to the first function performing device when the first verification information is obtained by decrypting the first signature information and the result information request is received from the first function performing device, wherein the first function performing device comprises a first function performing unit that executes a first function when the result information is received from the second function performing device, and the second function performing device has a second verification information sending unit that sends second verification information to the terminal device when a second function performing instruction is given to the second function performing device from the target user and the second function performing device accepts access to the second function performing device of the terminal device, wherein the terminal device receives the second verification information from the second function performing device, andThe authentication system may further include a second verification information transmitting unit that generates second signature information by encrypting the second verification information using the private key and transmits the second signature information to the second function performing device when the second authentication of the target user performed by the terminal device is successful, a second decryption unit that decrypts the second signature information using the public key when the second signature information is received from the terminal device, and a second function performing unit that performs the second function when the second verification information is obtained by decrypting the second signature information.

[0006] Furthermore, a first function performing device disclosed in this specification includes a result information request sending unit that, when a first function performing instruction is given from a target user to the first function performing device, sends a result information request to a second function performing device, requesting the transmission of result information indicating that authentication of the target user has been successful, and the second function performing device is operable according to a predetermined authentication method using a pair of keys, and a function performing unit that executes a first function when the result information is received from the second function performing device. A terminal device operable according to the predetermined authentication method accesses the second function performing device in response to the first function performing instruction being given to the first function performing device, receives first verification information from the second function performing device, and, when first authentication of the target user performed by the terminal device is successful, generates first signature information by encrypting the first verification information using a private key of the pair of keys and transmits the first signature information to the second function performing device, and the second function performing device then accesses the second function performing device and receives first verification information from the second function performing device. and, when a second function execution instruction is given to the second function performing device from the target user to access the second function performing device, the terminal device may further receive second verification information from the second function performing device when the second function performing instruction is given to the second function performing device from the target user, and when a second authentication of the target user performed by the terminal device is successful, generate second signature information by encrypting the second verification information using the private key and transmit the second signature information to the second function performing device; and, when the second signature information is received from the terminal device, the second function performing device may further decrypt the second signature information using the public key, and execute the second function when the second verification information is obtained by decrypting the second signature information.

[0007] The second function performing device disclosed in this specification may be operable according to a predetermined authentication method using a pair of keys. The second function performing device may include a first verification information transmitting unit that transmits first verification information to the terminal device when a terminal device operable according to the predetermined authentication method accesses the second function performing device in response to a first function performing instruction being given from a target user to the first function performing device, the first function performing device transmitting a result information request to the second function performing device in response to the first function performing instruction being given from the target user to the first function performing device, the result information request requesting transmission of result information indicating that authentication of the target user has been successful, the terminal device receiving the first verification information from the second function performing device and, if first authentication of the target user performed by the terminal device is successful, encrypting the first verification information using a private key of the pair of keys to generate first signature information and transmitting the first signature information to the second function performing device in response to the transmission of the first verification information to the terminal device. a first decryption unit that decrypts the first signature information using a public key of the pair of keys when signature information of the first function performing device is received; a result information request receiving unit that receives the result information request from the first function performing device; a result information sending unit that sends the result information to the first function performing device when the first verification information is obtained by decrypting the first signature information and the result information request is received from the first function performing device, the first function performing device executing the first function when the result information is received from the second function performing device; and a second verification information sending unit that sends second verification information to the terminal device when a second function performing instruction is given to the second function performing device from the target user and the terminal device accepts access to the second function performing device, the terminal device receiving the second verification information from the second function performing device and encrypting the second verification information using the private key when a second authentication of the target user executed by the terminal device is successful,The authentication system may include a second verification information transmitting unit that generates second signature information and transmits the second signature information to the second function performing device, a second decryption unit that decrypts the second signature information using the public key when the second signature information is received from the terminal device, and a function performing unit that performs the second function when the second verification information is obtained by decrypting the second signature information.

[0008] According to the above configuration, the first function performing device transmits a result information request to the second function performing device when a first function performing instruction is given to the first function performing device from the target user. The second function performing device transmits first verification information to the terminal device when it accepts access to the second function performing device from the terminal device. The terminal device receives the first verification information from the second function performing device, and when the first authentication of the target user is successful, generates first signature information by encrypting the first verification information using a private key and transmits the first signature information to the second function performing device. When the second function performing device receives the first signature information from the terminal device, it decrypts the first signature information using a public key. When the second function performing device obtains the first verification information by decrypting the first signature information and receives a result information request from the first function performing device, it transmits result information to the first function performing device. When the first function performing device receives result information from the second function performing device, it executes the first function. Therefore, a second function performing device that operates according to a predetermined authentication method that uses a pair of keys can be used to cause a first function performing device to perform a first function.

[0009] Furthermore, the second function performing device transmits second verification information to the terminal device when a second function performing instruction is given to the second function performing device from the target user and the terminal device accepts access to the second function performing device. When the second authentication of the target user is successful, the terminal device generates second signature information by encrypting the second verification information using the private key and transmits the second signature information to the second function performing device. When the second function performing device receives the second signature information from the terminal device, it decrypts the second signature information using the public key. When the second verification information is obtained by decrypting the second signature information, the second function performing device executes the second function. In this way, the second function performing device uses the same public key when causing the first function performing device to perform the first function and when causing the second function performing device to perform the second function.

[0010] Another communication system disclosed in this specification may include a first function executing device, a second function executing device that is capable of operating according to a predetermined authentication method using a pair of keys and is different from the first function executing device, and a third function executing device that is different from the first function executing device and the second function executing device. the first function performing device comprises a first result information request sending unit that, when a first function performing instruction is given from a target user to the first function performing device, sends to the second function performing device a first result information request requesting transmission of first result information indicating that authentication of the target user has been successful; and the second function performing device comprises a first verification information sending unit that, in response to the first function performing instruction being given to the first function performing device, sends first verification information to the terminal device when accepting access to the second function performing device from a terminal device operable according to the predetermined authentication method, and the terminal device receives the first verification information from the second function performing device, and, when first authentication of the target user performed by the terminal device is successful, encrypts the first verification information using a private key of the pair of keys to generate first signature information, and a first decryption unit that, when the first signature information is received from the terminal device in response to transmitting the first verification information to the terminal device, decrypts the first signature information using a public key of the pair of keys; a first result information request receiving unit that receives the first result information request from the first function performing device; and a first result information sending unit that, when the first verification information is obtained by decrypting the first signature information and the first result information request is received from the first function performing device, transmits the first result information to the first function performing device, wherein the first function performing device comprises a first function performing unit that executes a first function when the first result information is received from the second function performing device; and the third function performing device, when a second function performing instruction is given to the third function performing device from the target user,a second result information request sending unit that sends to the second function performing device a second result information request that requests transmission of second result information indicating that authentication of the target user has been successful, and the second function performing device has a second verification information sending unit that sends second verification information to the terminal device when the second function performing device accepts access to the second function performing device in response to the second function performing instruction being given to the third function performing device, and the terminal device receives the second verification information from the second function performing device, and when second authentication of the target user performed by the terminal device is successful, encrypts the second verification information using the private key to generate second signature information and sends the second signature information to the second function performing device. a second decryption unit that, when the second signature information is received from the terminal device in response to transmitting the second verification information to the terminal device, decrypts the second signature information using the public key; a second result information request receiving unit that receives the second result information request from the third function performing device; and a second result information sending unit that, when the second verification information is obtained by decrypting the second signature information and the second result information request is received from the third function performing device, transmits the second result information to the third function performing device, and the third function performing device may comprise a second function performing unit that executes a second function when the second result information is received from the second function performing device.

[0011] Another first function performing device disclosed in the present specification includes a result information request sending unit that, when a first function performing instruction is given from a target user to the first function performing device, sends a first result information request to a second function performing device, requesting transmission of first result information indicating that authentication of the target user has been successful, wherein the second function performing device is operable according to a predetermined authentication method using a pair of keys, and a function performing unit that executes a first function when the first result information is received from the second function performing device. A terminal device operable according to the predetermined authentication method accesses the second function performing device in response to the first function performing instruction being given to the first function performing device, receives first verification information from the second function performing device, and, when first authentication of the target user performed by the terminal device is successful, generates first signature information by encrypting the first verification information using a private key of the pair of keys and transmits the first signature information to the second function performing device, and the second function performing device receives the first signature information from the terminal device. and a third function performing device, different from the first and second function performing devices, when a second function performing instruction is given from the target user to the third function performing device, sends a second result information request to the second function performing device, requesting transmission of second result information indicating that authentication of the target user has been successful; and the terminal device, in response to the second function performing instruction being given to the third function performing device, further accesses the second function performing device to receive second verification information from the second function performing device, and, when the second authentication of the target user performed by the terminal device is successful, encrypts the second verification information using the private key to generate second signature information and transmits the second signature information to the second function performing device; and the second function performing device furtherWhen the second signature information is received from the terminal device, the second signature information is decrypted using the public key, the second verification information is obtained by decrypting the second signature information, and when the second result information request is received from the third function performing device, the second result information is transmitted to the third function performing device, and the third function performing device may further execute the second function when the second result information is received from the second function performing device.

[0012] Furthermore, another second function performing device disclosed in the present specification may be operable according to a predetermined authentication method using a pair of keys. The second function performing device includes a first verification information transmitting unit that transmits first verification information to the terminal device when a terminal device operable according to the predetermined authentication method is accepted for access to the second function performing device in response to a first function performing instruction being given from a target user to the first function performing device different from the second function performing device, the first function performing device transmitting a first result information request to the second function performing device in response to the first function performing instruction being given to the first function performing device, the first result information request requesting transmission of first result information indicating that authentication of the target user has been successful, the terminal device receiving the first verification information from the second function performing device and, if first authentication of the target user executed by the terminal device is successful, encrypting the first verification information using a private key of the pair of keys to generate first signature information and transmitting the first signature information to the second function performing device in response to the transmission of the first verification information to the terminal device. a first decryption unit that decrypts the first signature information using a public key of the pair of keys when signature information is received; a first result information request receiving unit that receives the first result information request from the first function performing device; a first result information transmission unit that transmits the first result information to the first function performing device when the first verification information is obtained by decrypting the first signature information and the first result information request is received from the first function performing device, the first function performing device executing a first function when the first result information is received from the second function performing device; and a second verification information transmission unit that transmits second verification information to the terminal device when the terminal device accepts access to the second function performing device in response to a second function performing instruction being given from the target user to a third function performing device different from the first function performing device and the second function performing device, the third function performing device in response to the second function performing instruction being given to the third function performing devicethe second verification information transmitting unit transmits to the second function performing device a second result information request requesting transmission of second result information indicating that authentication of the target user has been successful, the terminal device receiving the first verification information from the second function performing device and, if second authentication of the target user performed by the terminal device is successful, encrypting the second verification information using the private key to generate second signature information and transmitting the second signature information to the second function performing device; and a second decryption unit that decrypts the second signature information by using the public key when the second signature information is obtained, a second result information request receiving unit that receives the second result information request from the third function performing device, and a second result information sending unit that sends the second result information to the third function performing device when the second verification information is obtained by decrypting the second signature information and the second result information request is received from the third function performing device, wherein the third function performing device executes the second function when the second result information is received from the second function performing device.

[0013] According to the above configuration, the first function performing device transmits a first result information request to the second function performing device when a first function performing instruction is provided from the target user to the first function performing device. The second function performing device transmits first verification information to the terminal device when it accepts access from the terminal device to the second function performing device. The terminal device receives the first verification information from the second function performing device, and when the first authentication of the target user is successful, generates first signature information by encrypting the first verification information using a private key and transmits the first signature information to the second function performing device. When the second function performing device receives the first signature information from the terminal device, it decrypts the first signature information using a public key. When the second function performing device obtains the first verification information by decrypting the first signature information and receives a first result information request from the first function performing device, it transmits the first result information to the first function performing device. When the first result information is received from the second function performing device, the first function performing device executes the first function. Therefore, a second function performing device that operates according to a predetermined authentication method that uses a pair of keys can be used to cause a first function performing device to perform a first function.

[0014] Furthermore, the third function performing device transmits a second result information request to the second function performing device when a second function performing instruction is provided from the target user to the third function performing device. The second function performing device transmits second verification information to the terminal device when accepting access from the terminal device to the second function performing device. The terminal device receives the second verification information from the second function performing device, and when the second authentication of the target user is successful, generates second signature information by encrypting the second verification information using the private key and transmits the second signature information to the second function performing device. When the second function performing device receives the second signature information from the terminal device, it decrypts the second signature information using the public key. When the second function performing device obtains the second verification information by decrypting the second signature information and receives a second result information request from the third function performing device, it transmits the second result information to the third function performing device. When the third function performing device receives the second result information from the second function performing device, it executes the second function. In this way, the second function performing device uses the same public key when causing the first function performing device to perform the first function and when causing the third function performing device to perform the second function.

[0015] Also, the above-mentioned first function executing device and the above-mentioned second function executing device control method, computer program for the function executing device, and storage medium for storing the computer program are novel and useful. Also, the above-mentioned first function executing device, the above-mentioned second function executing device, and the above-mentioned third function executing device are novel and useful. Also, the above-mentioned first function executing device, the above-mentioned second function executing device, the above-mentioned third function executing device, and a communication system including a terminal device are novel and useful. [Brief explanation of the drawings]

[0016] [Figure 1] 1 shows the configuration of a communication system. [Figure 2] An example of each table is shown below. [Figure 3] FIG. 10 illustrates a sequence diagram of a registration process according to an embodiment. [Figure 4] FIG. 10 shows a sequence diagram of a first setting change process according to the embodiment. [Figure 5] FIG. 10 shows a sequence diagram of a second setting change process according to the embodiment. [Figure 6] FIG. 10 shows a sequence diagram of a third setting change process according to the embodiment. [Figure 7] FIG. 2 shows a sequence diagram of a printing process according to an embodiment. [Figure 8] FIG. 10 illustrates a sequence diagram of a batch setting process according to an embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0017] (Example) (Configuration of communication system 2; Figure 1) As shown in Fig. 1, the communication system 2 includes a plurality of MFPs (abbreviation of Multifunction Peripherals) 10A to 10C, a terminal device 100, and a PC 200. The MFPs 10A to 10C, the terminal device 100, and the PC 200 belong to the same LAN (abbreviation of Local Area Network) 4 and can communicate with each other via the LAN 4. In this embodiment, the terminal device 100 and the PC 200 are used by the same user. Furthermore, the user of the terminal device 100 is the administrator of the MFPs 10A to 10C.

[0018] (Configuration of MFP10A to 10C) The MFP 10A is a peripheral device (for example, a peripheral device of the terminal device 100) that can perform functions such as printing, scanning, copying, and web server functions. The web server function is a function that transmits web page data representing a web page to an external device in response to the external device accessing the web server in the MFP 10A. The MFP 10A is assigned a device ID "dv1" to identify the MFP 10A.

[0019] The MFP 10A includes an operation unit 12, a display unit 14, a print execution unit 16, a scan execution unit 18, a communication interface 20, and a control unit 30. In the following, the interface will be simply referred to as "I / F."

[0020] Operation unit 12 has a plurality of keys. A user can input various instructions to MFP 10A by operating operation unit 12. Display unit 14 is a display for displaying various information. Note that display unit 14 may function as a touch panel (i.e., operation unit 12).

[0021] The print execution unit 16 has a printing mechanism such as an inkjet system or a laser system. The scan execution unit 18 has a scanning mechanism such as a CCD (abbreviation of Charge Coupled Device) image sensor or a CIS (abbreviation of Contact Image Sensor). The communication I / F 20 is connected to the LAN 4. The communication I / F 20 may be a wireless I / F or a wired I / F.

[0022] The control unit 30 includes a CPU 32 and a memory 34A. The CPU 32 executes various processes in accordance with a program 36A stored in the memory 34A. The MFP 10A can operate in accordance with the FIDO (short for Fast Identity Online) authentication method, which uses a pair of keys. The FIDO authentication method is an authentication method that uses a pair of keys, i.e., a private key and a public key. The FIDO authentication method is also an authentication method that performs user authentication using biometric authentication (e.g., fingerprint authentication, voiceprint authentication, or facial authentication) instead of password authentication. In this embodiment, the MFP 10A operates as a so-called authentication server in the FIDO authentication method. The memory 34A is configured with a volatile memory, a non-volatile memory, and the like. The memory 34A further stores a user table 38A and a public key PK1. The public key PK1 is used when performing authentication in accordance with the FIDO authentication method (hereinafter simply referred to as "FIDO authentication").

[0023] The MFP 10B has the same structure as the MFP 10A, except that the information stored in the memory 34B is different. The memory 34B stores a program 36B, a user table 38B, and FIDO information 40B. The program 36B is the same as the program 36A. The FIDO information 40B is information indicating the MFP in which a public key for FIDO authentication is registered. The FIDO information 40B is registered by the administrator of the MFP 10B. The MFP 10B is assigned a device ID "dv2" for identifying the MFP 10B.

[0024] The MFP 10C has the same structure as the MFP 10C, except that the information stored in the memory 34C is different. The memory 34C stores a program 36C, a user table 38C, and FIDO information 40C. The program 36C is the same as the program 36A. The FIDO information 40C is registered by the administrator of the MFP 10C. The MFP 10C is assigned a device ID "dv3" for identifying the MFP 10C.

[0025] (Configuration of terminal device 100) The terminal device 100 is a portable terminal device such as a mobile phone (for example, a smartphone), a PDA, a tablet PC, etc. The terminal device 100 includes an operation unit 112, a display unit 114, a communication I / F 120, and a control unit .

[0026] The operation unit 112 is, for example, a touch panel. The operation unit 112 can accept various instructions. The operation unit 112 also functions as a fingerprint authentication unit. The display unit 114 is a display for displaying various information. The communication I / F 120 is connected to the LAN 4.

[0027] The control unit 130 includes a CPU 132 and a memory 134. The CPU 132 executes various processes in accordance with an OS (abbreviation for Operating System) program 136 stored in the memory 134. The terminal device 100 is operable in accordance with the FIDO authentication method. In this embodiment, the terminal device 100 operates as a so-called authenticator in the FIDO authentication method. The memory 134 is configured by a volatile memory, a non-volatile memory, etc. The memory 134 further stores fingerprint information 138, a batch setting application 140, and a private key SK1. The fingerprint information 138 is information related to the fingerprint of a user who uses the terminal device 100. The batch setting application 140 is an application for changing the settings of two or more MFPs at the same time. The private key SK1 is used when performing FIDO authentication.

[0028] (User tables 38A to 38C; Figure 2) Next, the user tables 38A to 38C in the MFPs 10A to 10C will be described with reference to FIG.

[0029] In user table 38A in MFP 10A, restriction information and job IDs are stored in association with each other. The restriction information is information that identifies one or more functions that the user is permitted to use from among the print function, scan function, and copy function that can be executed by MFP 10A. "OK" indicates that use is permitted, and "NG" indicates that use is not permitted. The job ID is information for identifying print data. Although not shown, the print data is associated with the job ID. In user tables 38B and 38C in MFPs 10B and 10C, restriction information and job IDs are also stored in association with each other.

[0030] (Registration process; Figure 3) Next, a registration process for registering information for performing FIDO authentication in the MFP 10A and the terminal device 100 will be described with reference to FIG. 3. Note that, hereinafter, each device (e.g., MFP 10A) will be described as the subject, rather than the CPU of each device (e.g., CPU 32 of MFP 10A). Furthermore, communication performed by each device is performed via the communication I / F of each device (e.g., communication I / F 20 of MFP 10A). Therefore, hereinafter, when describing processing related to communication via a communication I / F, the expression "via a communication I / F" will be omitted.

[0031] 3, print "OK", scan "OK", and copy "NG" are stored in association with each other in user tables 38A to 38C of MFPs 10A to 10C. Furthermore, fingerprint information 138 is stored in memory 134 of terminal device 100.

[0032] When the terminal device 100 receives input of the IP address "IPa" assigned to the MFP 10A in T10, it transmits a top screen data request to the MFP 10A in T12.

[0033] At T12, when the MFP 10A receives the top screen data request from the terminal device 100, it determines that neither the public key used for FIDO authentication nor the FIDO information is stored in the memory 34A, and transmits first top screen data for displaying the first top screen data to the terminal device 100. The first top screen includes a FIDO registration button for registering information for performing FIDO authentication.

[0034] When the terminal device 100 receives the first top screen data from the MFP 10A in T14, the terminal device 100 displays the first top screen on the display unit 114 in T16. When the terminal device 100 accepts selection of the FIDO registration button in T20, the terminal device 100 transmits a FIDO registration request to the MFP 10A in T22.

[0035] When the MFP10A receives a FIDO registration request from the terminal device 100 at T22, it generates a verification code VC1, which is a unique string of characters, at T30, stores the generated verification code VC1 in memory 34A, and sends an authentication request including the generated verification code VC1 to the terminal device 100 at T32.

[0036] When the terminal device 100 receives an authentication request from the MFP 10A in T32, it displays a fingerprint authentication screen in T34. A message requesting execution of fingerprint authentication is displayed on the fingerprint authentication screen. The terminal device 100 accepts a fingerprint authentication operation in T36. In this case, the terminal device 100 determines that fingerprint authentication has been successful because the fingerprint information acquired by the fingerprint authentication operation matches the fingerprint information 138 in the memory 134. Next, the terminal device 100 generates a pair of keys (i.e., a private key SK1 and a public key PK1) to be used for FIDO authentication in T40, and stores the private key SK1 in the memory 134 in T42. Next, the terminal device 100 transmits an authentication response including the generated public key PK1 and the received verification code VC1 to the MFP 10A in T44.

[0037] When the MFP 10A receives the authentication response from the terminal device 100 in T44, it determines that the verification code VC1 in the authentication response matches the verification code VC1 stored in memory 34A (see T30), and determines that user authentication of the user of terminal device 100 (hereinafter, sometimes referred to as the "target user") has been successful. In this case, the MFP 10A stores the public key PK1 in the received authentication response in memory 34A in T46. Next, the MFP 10A transmits registration completion screen data to the terminal device 100 in T50. The MFP 10A also erases the verification code VC1 from memory 34A.

[0038] When the terminal device 100 receives registration completion screen data from the MFP 10A in T50, it displays a registration completion screen including a message indicating that the registration process has been completed on the display unit 114 in T52. This allows the user to know that registration of a pair of keys used for FIDO authentication has been completed. When the processing of T52 ends, the registration process ends. This allows the user of the terminal device 100 to use FIDO authentication. Note that the user of the terminal device 100 (i.e., the administrator of the MFPs 10A to 10C) registers FIDO information 40B and 40C in memories 34B and 34C of the MFPs 10B and 10C. In this embodiment, the FIDO information 40B and 40C is the device ID "dv1" of the MFP 10A.

[0039] (First setting change process; Figure 4) Next, with reference to Fig. 4, a first setting change process for changing restriction information in user table 38A of MFP 10A using the web server function of MFP 10A will be described. Fig. 4 shows the state after the registration process of Fig. 3 is completed. That is, public key PK1 is stored in memory 34A of MFP 10A. Furthermore, private key SK1 is stored in memory 134 of terminal device 100. Furthermore, FIDO information 40B and 40C are stored in memories 34B and 34C of MFPs 10B and 10C, respectively. T110 and T112 are the same as T10 and T12 in Fig. 3.

[0040] At T112, when the MFP 10A receives the top screen data request from the terminal device 100, it determines that the public key PK1 used for FIDO authentication is stored in the memory 34A, and transmits second top screen data for displaying the second top screen data to the terminal device 100. The second top screen includes a FIDO login button (i.e., a button for using the web server function of the MFP 10A) for logging in to the MFP 10A using FIDO authentication.

[0041] When the terminal device 100 receives the second top screen data from the MFP 10A in T114, in T116, the terminal device 100 displays the second top screen on the display unit 114. When the terminal device 100 accepts selection of the FIDO login button in T120, in T122, the terminal device 100 transmits an FIDO login request to the MFP 10A.

[0042] 3 except that verification code VC2 is used. If terminal device 100 determines that fingerprint authentication is successful, in T140, it generates signature information SI1 by encrypting the received verification code VC2 using private key SK1 stored in memory 134. Next, in T142, terminal device 100 transmits an authentication response including the generated signature information SI1 to MFP 10A.

[0043] When the MFP 10A receives an authentication response from the terminal apparatus 100 in T142, it decrypts the signature information SI1 in the authentication response using the public key PK1 in the memory 34A in T144. In this embodiment, the verification code VC2 is obtained by decrypting the signature information SI1 using the public key PK1. The MFP 10A determines that the decrypted signature information SI1 (i.e., the verification code VC2) matches the verification code VC2 stored in the memory 34A (see T130), and determines that user authentication of the target user has been successful. In this case, the MFP 10A generates a token tk1, which is authentication information for the terminal apparatus 100 to communicate with the MFP 10A, in T150, and transmits setting change screen data including the generated token tk1 to the terminal apparatus 100 in T152.

[0044] When the terminal device 100 receives the setting change screen data from the MFP 10A in T152, it displays the setting change screen on the display unit 14 in T154. The setting change screen is a screen for changing various settings (for example, communication settings, restriction information, default print settings, etc.). When the terminal device 100 accepts an operation to change the restriction information corresponding to the scan function in the user table 38A of the MFP 10A from "OK" to "NG" in T160, it transmits a setting change request including scan "NG" and token tk1 to the MFP 10A in T162.

[0045] When the MFP 10A receives a settings change request from the terminal device 100 in T162, it identifies the token tk1 in the request, determines that authentication using the token tk1 was successful, and in T164 changes the restriction information corresponding to the scan function in the user table 38A from "OK" to "NG." When the processing of T164 ends, the first setting change process ends.

[0046] (Second setting change process; Figure 5) Next, a second setting change process for changing the restriction information in user table 38B of MFP 10B using the web server function of MFP 10B will be described with reference to Fig. 5. The initial state in Fig. 5 is the same as the initial state in Fig. 4.

[0047] When the terminal apparatus 100 receives input of the IP address "IPb" assigned to the MFP 10B in T210, it transmits a top screen data request to the MFP 10B in T212.

[0048] When the MFP 10B receives the top screen data request from the terminal device 100 in T212, it determines that the FIDO information 40B is stored in the memory 34B, and in T214 transmits second top screen data to the terminal device 100. T216 to T222 are the same as T116 to T122 in FIG. 4 except that the communication target is the MFP 10B.

[0049] When the MFP 10B receives a FIDO login request from the terminal apparatus 100 in T222, it identifies the device ID "dv1" indicated by the FIDO information 40B in the memory 34B, and transmits an access URL request to the MFP 10A identified by the device ID "dv1" in T224. The access URL request is a signal requesting transmission of a URL for the terminal apparatus 100 to access the MFP 10A. Next, in T226, the MFP 10B receives from the MFP 10A the access URL, which is location information of the MFP 10A, and in T228 transmits a redirect instruction including the received access URL to the terminal apparatus 100. The redirect instruction is an instruction to cause the terminal apparatus 100 to access the MFP 10A using the access URL in the redirect instruction as a destination URL.

[0050] Furthermore, at T230, MFP 10B transmits to MFP 10A a result information request requesting transmission of result information indicating that user authentication of the target user has been successful. At this point, user authentication of the target user has not been performed. Therefore, at T232, MFP 10B receives from MFP 10A standby information indicating that user authentication of the target user has not been performed. Note that after T232, MFP 10B periodically transmits result information requests to MFP 10A.

[0051] When the terminal device 100 receives the redirect instruction from the MFP 10B in T228, it transmits an authentication start request including the access URL in the redirect instruction as a destination URL to the MFP 10A in T240. In this way, in order for the terminal device 100 to receive the access URL from the MFP 10B, it is not necessary to register the access URL in advance in the memory 134 of the terminal device 100. Furthermore, the target user is not required to input the access URL.

[0052] When the MFP 10A receives an authentication start request from the terminal device 100 in T240, the MFP 10A generates a verification code VC3, which is a unique character string, in T242 and stores the generated verification code VC3 in memory 34A. T244 to T248 and T250 to T254 are similar to T132 to T136 and T140 to T144 in FIG. 4, respectively, except that the verification code VC3 and signature information SI2 are used. In this case, in T250, the terminal device 100 generates signature information SI2 by encrypting the received verification code VC3 using private key SK1 stored in memory 134. In T254, the MFP 10A decrypts the signature information SI2 using public key PK1 to obtain the verification code VC3, and therefore determines that user authentication of the target user has been successful. In T260, the MFP 10A transmits result information indicating that user authentication of the target user has been successful to the terminal device 100.

[0053] As described above, MFP 10B periodically transmits a result information request. Therefore, MFP 10B transmits the result information request to MFP 10A at T270, which is a time point after user authentication of the target user is successful. Because user authentication of the target user is successful, MFP 10B receives result information from MFP 10A at T272. In response to receiving the result information, MFP 10B terminates the periodic transmission of the result information request to MFP 10A. Note that, in a modified example, if no result information has been received when a predetermined time (e.g., one minute) has elapsed since the first transmission of the result information request, MFP 10B may terminate the periodic transmission of the result information request to MFP 10A. Next, MFP 10B generates a token tk2, which is authentication information for terminal apparatus 100 to communicate with MFP 10B, at T280, and transmits setting change screen data including the generated token tk2 to terminal apparatus 100 at T282. As described above, after transmitting the access URL to the terminal device 100, the MFP 10B transmits a result information request to the MFP 10A (T230, T270). Receipt of the access URL by the terminal device 100 triggers execution of FIDO authentication, that is, user authentication of the target user. Therefore, it is possible to reduce the possibility that a result information request will be transmitted to the MFP 10A before user authentication of the target user is executed.

[0054] T284 to T292 are the same as T154 to T162 in FIG. 4, except that the communication target is MFP 10B and token tk2 is used. When MFP 10B receives a setting change request from terminal device 100 in T292, it identifies token tk2 in the request, determines that authentication using token tk2 was successful, and changes the restriction information corresponding to the scan function in user table 38B from "OK" to "NG" in T294. When the processing of T294 ends, the second setting change process ends. As described above, in order to receive token tk1 from MFP 10B that received the result information, the terminal device 100 can communicate with MFP 10B, which is different from MFP 10A that operated according to FIDO authentication, i.e., can use the web server function of MFP 10B.

[0055] (Third setting change process; Figure 6) Next, a third setting change process for changing the restriction information in user table 38C of MFP 10C using the web server function of MFP 10C will be described with reference to Fig. 6. The initial state of Fig. 6 is the same as the initial state of Fig. 4.

[0056] When the terminal apparatus 100 receives input of the IP address "IPc" assigned to the MFP 10C in T310, it transmits a top screen data request to the MFP 10C in T312.

[0057] When the MFP 10C receives the top screen data request from the terminal device 100 in T312, it determines that the FIDO information 40C is stored in the memory 34C, and in T314 transmits second top screen data to the terminal device 100. T316 to T322 are the same as T216 to T222 in FIG. 5 except that the communication target is the MFP 10C.

[0058] When the MFP 10C receives an FIDO login request from the terminal device 100 at T322, it identifies the device ID "dv1" indicated by the FIDO information 40C in the memory 34C, and transmits an access URL request to the MFP 10A identified by the device ID "dv1" at T324. T324 to T328 are the same as T224 to T228 in FIG. 5 except that the communication target is the MFP 10C. The MFP 10C transmits a result information request to the MFP 10A at T330, and receives standby information from the MFP 10A at T332. After T332, the MFP 10C periodically transmits result information requests to the MFP 10A.

[0059] 5 except that the communication target is MFP 10C and that verification code VC4 and signature information SI3 are used. In this case, MFP 10A generates verification code VC4 in T342 and stores it in memory 34A. Then, terminal device 100 generates signature information SI3 by encrypting the received verification code VC4 using private key SK1 stored in memory 134 in T350. MFP 10A decrypts signature information SI3 using public key PK1 in T354, and because verification code VC4 is obtained, MFP 10A determines that user authentication of the target user has been successful, and transmits result information to terminal device 100 in T360.

[0060] Furthermore, at T370, which is a point in time after user authentication of the target user is successful, MFP 10C sends a result information request to MFP 10A, and at T372 receives the result information from MFP 10A. In response to receiving the result information, MFP 10C ends the periodic transmission of result information requests to MFP 10A. Next, at T380, MFP 10C generates token tk3, which is authentication information for terminal apparatus 100 to communicate with MFP 10C, and at T382, transmits setting change screen data including the generated token tk3 to terminal apparatus 100.

[0061] 5 except that the communication target is MFP 10C and token tk3 is used. When MFP 10C receives a settings change request from terminal device 100 in T392, it identifies token tk3 in the request, determines that authentication using token tk3 was successful, and changes the restriction information corresponding to the scan function in user table 38C from "OK" to "NG" in T394. When the processing of T394 ends, the third setting change process ends.

[0062] (Printing process; Figure 7) Next, a printing process in which printing is performed using MFP 10B will be described with reference to Fig. 7. The initial state in Fig. 7 is the same as the initial state in Fig. 4. Note that after the registration process in Fig. 3 is completed, the target user uses PC 200 to send print data to MFP 10B. Therefore, the job ID "job2" corresponding to the print data received from PC 200 is stored in user table 38B of MFP 10B.

[0063] When the MFP 10B accepts a print operation (i.e., a print instruction) in T410, it determines that FIDO information 40B is stored, identifies the device ID "dv1" indicated by the FIDO information 40B, and transmits an access URL request to the MFP 10A identified by the device ID "dv1" in T414. T414 to T462 are similar to T224 to T272 in FIG. 5 except that a verification code VC5 and signature information SI4 are used. In this case, the MFP 10A generates a verification code VC5 in T432 and stores it in the memory 34A. In T440, the terminal device 100 generates signature information SI4 by encrypting the received verification code VC5 using the private key SK1 stored in the memory 134. In T444, MFP10A determines that user authentication of the target user has been successful because it obtains verification code VC5 by decrypting signature information SI4 using public key PK1, and in T450 transmits result information to terminal device 100.

[0064] When the MFP 10B receives the result information from the MFP 10A in T462, it identifies the print data corresponding to the job ID "job2" stored in the user table 38B, and executes printing in accordance with the identified print data in T464. When the processing in T464 ends, the printing process ends.

[0065] (Bulk setting process; Figure 8) Next, a description will be given of a batch setting process for changing the restriction information stored in two MFPs 10B and 10C using batch setting application 140 stored in memory 134 of terminal device 100. The initial state in FIG. 8 is the same as the initial state in FIG. 4.

[0066] When the terminal device 100 accepts an operation to launch the batch setting application 140 in T510, it launches the batch setting application 140 and displays a home screen on the display unit 114 in T512. The home screen includes a device ID input field for inputting the device ID of the MFP whose settings are to be changed, and a setting selection field for selecting changes to various MFP settings (e.g., communication settings, restriction information, default print settings, etc.). When the terminal device 100 accepts input of device IDs "dv1" and "dv2" and a selection of scan "NG" in T514, it determines that two MFPs 10B and 10C have been selected, and in T520 transmits an authentication standby request to the MFP 10B identified by the device ID "dv1" written at the beginning of the device ID input field. The authentication standby request is a signal for requesting standby for execution of FIDO authentication.

[0067] When the MFP 10B receives an authentication standby request from the terminal apparatus 100 in T520, it transmits the authentication standby request to the MFP 10A in T522. Next, when the MFP 10B receives response information from the MFP 10A in T524 indicating that the transmission of the authentication standby request was successful, it transmits acceptance success information to the terminal apparatus 100 in T526. T528 and T530 are the same as T230 and T232 in FIG. 5, respectively.

[0068] When the terminal device 100 receives the successful reception information from the MFP 10B in T526, it identifies the device ID "dv2" entered next to the device ID "dv1" in the device ID input field, and transmits an authentication execution request to the MFP 10C identified by the device ID "dv2" in T540. The authentication execution request is a signal for requesting execution of user authentication using FIDO authentication.

[0069] When the MFP 10B receives an authentication execution request from the terminal apparatus 100 in T540, it transmits an access URL request to the MFP 10A in T542. T544 to T550 and T560 are the same as T326 to T332 and T340 in Fig. 6, respectively. After that, processing similar to T242 to T260 in Fig. 5 is executed between the MFP 10A and the terminal apparatus 100, that is, user authentication of the target user using FIDO authentication is successful.

[0070] T570 and T572 are the same as T270 and T272 in Fig. 5. When the MFP 10B receives the result information from the MFP 10A at T572, the MFP 10B generates a token tk4 at T580 and transmits the result information including the generated token tk4 to the terminal device 100 at T582.

[0071] When the terminal apparatus 100 receives the result information from the MFP 10B in T582, it transmits a settings change request including the scan “NG” and the received token tk4 to the MFP 10B in T584. T586 is the same as T294 in FIG.

[0072] T590 to T604 are the same as T570 to T584 except that the communication target is the MFP 10C and that token tk5 is used. T606 is the same as T394 in Fig. 6. When the processing of T606 ends, the print process ends.

[0073] As described above, when a target user desires to change the restriction information of MFPs 10B and 10C, the target user only needs to successfully complete user authentication once. That is, the target user does not need to perform user authentication to change the restriction information of MFP 10B and user authentication to change the restriction information of MFP 10C. This improves user convenience.

[0074] (Effects of this embodiment) According to the above configuration, when a FIDO login request is provided to MFP 10B from the target user (T220, T222 in FIG. 5), MFP 10B transmits a result information request to MFP 10A (T230, T270). When MFP 10A accepts access to MFP 10A from terminal apparatus 100 (T240), MFP 10A transmits verification code VC3 to terminal apparatus 100 (T244). When terminal apparatus 100 receives verification code VC3 from MFP 10A (T244), and fingerprint authentication of the target user (i.e., user authentication) is successful (T248), MFP 10B encrypts verification code VC3 using private key SK1 to generate signature information SI2 (T250), and transmits signature information SI2 to MFP 10A (T252). When the MFP 10A receives signature information SI2 from the terminal device 100 (T252), it decrypts the signature information SI2 using the public key PK1 (T254). When the MFP 10A obtains the verification code VC3 by decrypting the signature information SI2 (T254) and receives a result information request from the MFP 10B (T270), it transmits the result information to the MFP 10B (T272). When the MFP 10B receives the result information from the MFP 10A (T272), it executes the web server function (T282). Therefore, it is possible to cause the MFP 10B to execute the web server function by using the MFP 10A that operates in accordance with the FIDO authentication method.

[0075] Furthermore, when a FIDO login request is provided to the MFP 10A from the target user (T120 and T122 in FIG. 4) and the MFP 10A accepts access to the MFP 10A from the terminal device 100 (T122), the MFP 10A transmits a verification code VC2 to the terminal device 100 (T132). When fingerprint authentication of the target user (i.e., user authentication) is successful, the terminal device 100 generates signature information SI1 by encrypting the verification code VC2 using the private key SK1 (T140) and transmits the signature information SI1 to the MFP 10A (T142). When the MFP 10A receives the signature information SI1 from the terminal device 100 (T142), the MFP 10A decrypts the signature information SI1 using the public key PK1 (T144). When the MFP 10A obtains the verification code VC2 by decrypting the signature information SI1 (T144), the MFP 10A executes a web server function (T152). In this way, MFP 10A uses the same public key PK1 when causing MFP 10B to execute the web server function (FIG. 5) and when causing MFP 10A to execute the web server function (FIG. 4).

[0076] Furthermore, according to the above configuration, when an FIDO login request is provided to MFP 10B from the target user (T220, T222 in FIG. 5), MFP 10B transmits a result information request to MFP 10A (T230, T270). When MFP 10A accepts access to MFP 10A from terminal apparatus 100 (T240), MFP 10A transmits verification code VC3 to terminal apparatus 100 (T244). When terminal apparatus 100 receives verification code VC3 from MFP 10A (T244), and fingerprint authentication of the target user (i.e., user authentication) is successful (T248), MFP 10B encrypts verification code VC3 using private key SK1 to generate signature information SI2 (T250), and transmits signature information SI2 to MFP 10A (T252). When the MFP 10A receives signature information SI2 from the terminal device 100 (T252), it decrypts the signature information SI2 using the public key PK1 (T254). When the MFP 10A obtains the verification code VC3 by decrypting the signature information SI2 (T254) and receives a result information request from the MFP 10B (T370), it transmits the result information to the MFP 10B (T272). When the MFP 10B receives the result information from the MFP 10A (T272), it executes the web server function (T282). Therefore, it is possible to cause the MFP 10B to execute the web server function by using the MFP 10A that operates in accordance with the FIDO authentication method.

[0077] Furthermore, when a FIDO login request is provided to MFP 10C from the target user (T320, T322 in FIG. 6), MFP 10C transmits a result information request to MFP 10A (T330, T370). When MFP 10A accepts access to MFP 10A from terminal apparatus 100 (T340), MFP 10A transmits verification code VC4 to terminal apparatus 100 (T344). When terminal apparatus 100 receives verification code VC4 from MFP 10A (T344), and fingerprint authentication of the target user (i.e., user authentication) is successful (T348), MFP 10C generates signature information SI3 by encrypting verification code VC4 using private key SK1 (T350), and transmits signature information SI3 to MFP 10A (T352). When MFP 10A receives signature information SI3 from terminal device 100 (T352), it uses public key PK1 to decrypt the signature information SI3 (T354). When MFP 10A obtains verification code VC4 by decrypting signature information SI3 (T354) and receives a result information request from MFP 10C (T370), it transmits result information to MFP 10C (T372). When MFP 10C receives result information from MFP 10A (T372), it executes the web server function (T382). In this way, MFP 10A uses the same public key PK1 when causing MFP 10B to execute the web server function (FIG. 5) and when causing MFP 10C to execute the web server function (FIG. 6).

[0078] (Correspondence) In one aspect, MFP10B and MFP10A are examples of a "first function executing device" and a "second function executing device," respectively. The FIDO authentication method is an example of a "predetermined authentication method." T220 and T222 in FIG. 5 and T410 in FIG. 7 are examples of a "first function executing instruction." Verification codes VC3 and VC5 are examples of "first verification information." Fingerprint authentication T248 in FIG. 5 and T438 in FIG. 7 are examples of "first authentication." Signature information SI2 and SI4 are examples of "first signature information." The web server function and printing function of MFP10B are examples of a "first function." T120 and T122 in FIG. 4 are examples of a "second function executing instruction." Verification code VC2 is an example of "second verification information." Fingerprint authentication T136 in FIG. 4 is an example of "second authentication." Signature information SI1 is an example of "second signature information." The web server function of MFP 10A is an example of "second function." Token tk2 of T282 in FIG. 5 is an example of "token for a terminal device to communicate with a first function performing device." The access URL is an example of "location information of a second function performing device."

[0079] T230 and T270 in Fig. 5 and T420 and T460 in Fig. 7 are examples of processing executed by the "result information request sending unit" of the "first function executing device." T282 in Fig. 5 and T464 in Fig. 7 are examples of processing executed by the "first function executing unit" and the "function executing unit" of the "first function executing device."

[0080] T244 in FIG. 5 and T434 in FIG. 7 are examples of processing executed by the "first verification information transmitting unit" of the "second function performing device." T254 in FIG. 5 and T444 in FIG. 7 are examples of processing executed by the "first decryption unit" of the "second function performing device." T230 and T270 in FIG. 5 and T420 and T460 in FIG. 7 are examples of processing executed by the "result information request receiving unit" of the "second function performing device." T272 in FIG. 5 and T462 in FIG. 7 are examples of processing executed by the "result information transmitting unit" of the "second function performing device." T132 in FIG. 4 is an example of processing executed by the "second verification information transmitting unit" of the "second function performing device." T144 in FIG. 4 is an example of processing executed by the "second decryption unit" of the "second function performing device." T152 in FIG. 4 is an example of a process executed by the "second function executing unit" of the "second function executing device."

[0081] In another aspect, MFP10B, MFP10A, and MFP10C are examples of a "first function performing device," a "second function performing device," and a "third function performing device," respectively. The FIDO authentication method is an example of a "predetermined authentication method." T220 and T222 in FIG. 5 and T410 in FIG. 7 are examples of a "first function performing instruction." The result information of T272 in FIG. 5 and T462 in FIG. 7 are examples of "first result information." The result information requests of T230 in FIG. 5, T270 in FIG. 5, T420 in FIG. 7, and T460 in FIG. 7 are examples of "first result information requests." Verification codes VC3 and VC5 are examples of "first verification information." Fingerprint authentication of T248 in FIG. 5 and T438 in FIG. 7 are examples of "first authentication." Signature information SI2 and SI4 are examples of "first signature information." The web server function and print function of MFP 10B are examples of a "first function." T320 and T322 in FIG. 6 are examples of a "second function execution instruction." The result information of T372 in FIG. 6 is an example of "second result information." T330 in FIG. 6 and the result information request of T370 in FIG. 6 are examples of a "second result information request." Verification code VC4 is an example of "second verification information." Fingerprint authentication of T348 in FIG. 6 is an example of "second authentication." Signature information SI3 is an example of "second signature information." The web server function of MFP 10C is an example of a "second function." Token tk2 of T282 in FIG. 5 is an example of a "token for a terminal device to communicate with a first function executing device." The access URL is an example of "location information of a second function executing device."

[0082] T514 in FIG. 8 is an example of a "third function execution instruction." The authentication standby request of T522 in FIG. 8 is an example of a "first authentication acceptance request." T528 and T570 in FIG. 8 are examples of a "third result information request." The result information of T572 in FIG. 8 is an example of "third result information." The access URL request of T542 in FIG. 8 is an example of a "second authentication acceptance request." T548 and T590 in FIG. 8 are examples of a "fourth result information request." The result information of T592 in FIG. 8 is an example of "fourth result information." Verification code VC3 is an example of "third verification information." Fingerprint authentication of T248 in FIG. 5 cited in FIG. 8 is an example of "third authentication." Signature information SI2 is an example of "third signature information." The function of changing the restriction information of MFP 10B and the function of changing the restriction information of MFP 10C are examples of a "third function."

[0083] T230 and T270 in Fig. 5 and T420 and T460 in Fig. 7 are examples of processing executed by the "first result information request sending unit" of the "first function executing device." T282 in Fig. 5 and T464 in Fig. 7 are examples of processing executed by the "first function executing unit" of the "first function executing device."

[0084] T244 in FIG. 5 and T434 in FIG. 7 are examples of processing executed by the "first verification information transmitting unit" of the "second function performing device." T254 in FIG. 5 and T444 in FIG. 7 are examples of processing executed by the "first decryption unit" of the "second function performing device." T230 and T270 in FIG. 5 and T420 and T460 in FIG. 7 are examples of processing executed by the "first result information request receiving unit" of the "second function performing device." T272 in FIG. 5 and T462 in FIG. 7 are examples of processing executed by the "first result information transmitting unit" of the "second function performing device." T344 in FIG. 6 is an example of processing executed by the "second verification information transmitting unit" of the "second function performing device." T354 in FIG. 6 is an example of processing executed by the "second decryption unit" of the "second function performing device." T330 and T370 in Fig. 6 are examples of processing executed by the "second result information request receiving unit" of the "second function performing device." T372 in Fig. 6 is an example of processing executed by the "second result information transmitting unit" of the "second function performing device."

[0085] Although specific examples of the present invention have been described above in detail, these are merely examples and do not limit the scope of the claims. The technology described in the claims includes various modifications and variations of the specific examples exemplified above. Modifications of the above-mentioned embodiments are listed below.

[0086] 5, when MFP 10A receives a result information request from MFP 10B, MFP 10A may transmit the result information to terminal device 100, and terminal device 100 may transmit the result information to MFP 10B. That is, MFP 10A may transmit the result information to MFP 10B via terminal device 100.

[0087] (Second Modification) FIDO information 40B may not be stored in memory 34B of MFP 10B. In this modification, when MFP 10B receives an FIDO login request from terminal device 100 at T222 in FIG. 5 , MFP 10B transmits a search signal to multiple MFPs connected to LAN 4 to search for MFPs that store a public key used for FIDO authentication. Then, MFP 10B transmits an access URL request to an MFP (e.g., MFP 10A) that transmits a response signal to the search signal. Subsequent processing is similar to the processing from T226 onwards in FIG. 5 . In another modification, FIDO information (i.e., device ID “dv1”) may be stored in memory 134 of terminal device 100. In this modification, terminal device 100 transmits an FIDO login request including device ID “dv1” to MFP 10B at T222. In this case, in T224, the MFP 10B transmits an access URL request to the MFP 10A identified by the device ID “dv1” in the FIDO login request. The subsequent processing is the same as the processing from T226 onwards in FIG.

[0088] (Third Modification) A password may be stored in the memory 134 of the terminal device 100. In this modification, the terminal device 100 displays a screen requesting entry of a password on the display unit 114 at T34 in Fig. 3, T134 in Fig. 4, T246 in Fig. 5, T346 in Fig. 6, and T436 in Fig. 7.

[0089] (Fourth Modification) A public key PK1 and a public key different from public key PK1 (hereinafter, sometimes referred to as a "second public key") may be stored in memory 34A of MFP 10A, and a private key SK1 and a second private key corresponding to the second public key may be stored in memory 134 of terminal device 100. In this modification, FIDO authentication is performed using public key PK1 and private key SK1 in the first setting change process of FIG. 4 and the second setting change process of FIG. 5, and FIDO authentication is performed using the second public key and second private key in the third setting change process of FIG. 6. In this modification, MFP 10A and terminal device 100 may use a device ID to determine a pair of keys (i.e., a public key and a private key) to be used for FIDO authentication. In another variant, in the first setting change process of Figure 4, FIDO authentication is performed using a second public key and a second private key, and in the second setting change process of Figure 5 and the third setting change process of Figure 6, FIDO authentication is performed using a public key PK1 and a private key SK1.

[0090] 5, when MFP 10A receives a result information request from MFP 10B, it may generate a token and transmit result information including the generated token to MFP 10B at T272. In this modification, when MFP 10B receives result information from MFP 10A, it stores the token in the result information and transmits setting change screen data including the token to terminal device 100. In this modification, the "token transmission unit" can be omitted.

[0091] (Sixth Modification) The access URL may be pre-stored in the memory 34B of the MFP 10B. In this modification, when the MFP 10B receives an FIDO login request from the terminal device 100 at T222 in FIG. 5 , the MFP 10B transmits a redirect instruction including the access URL in the memory 34B to the terminal device 100. That is, T224 and T226 can be omitted. In this modification, the "location information transmission unit" can be omitted. In another modification, the access URL may be pre-stored in the memory 134 of the terminal device 100. In this modification, the terminal device 100 transmits an FIDO login request to the MFP 10B at T222, and then transmits an authentication start request including the access URL in the memory 134 as a destination URL to the MFP 10A. In this modification, T224 to T228 can be omitted. In this modification, the "location information transmission unit" can be omitted.

[0092] (Seventh Modification) The MFP 10B may send a result information request to the MFP 10A before sending the access URL request.

[0093] (Eighth Modification) In the user table 38A of the MFP 10A, a user ID, a public key, restriction information, and a job ID may be associated with each other. Furthermore, in the user tables 38B and 38C of the MFPs 10B and 10C, a user ID, restriction information, and a job ID may be associated with each other. In this modification, at T16 in FIG. 3, the first top screen displayed on the display unit 114 of the terminal device 100 includes a user ID input field for inputting a user ID. Upon receiving input of the user ID "U1" and selection of the FIDO registration button at T20, the terminal device 100 transmits a FIDO registration request including the user ID "U1" to the MFP 10A. Thereafter, processes similar to those at T30 to T44 are executed between the MFP 10A and the terminal device 100. Then, at T46, the MFP 10A stores the public key PK1 in the user table 38A in association with the user ID "U1." In this modification, the second top screen displayed on the terminal device 100 at T116 in FIG. 4, T216 in FIG. 5, and T316 in FIG. 6 also includes a user ID input field. Then, for example, at T216 in the second setting change process in FIG. 5, the terminal device 100 accepts input of the user ID "U1" and selection of the FIDO registration button. In this case, the terminal device 100 transmits a FIDO registration request including the user ID "U1" to the MFP 10B at T222, and the MFP 10B transmits an access URL request including the user ID "U1" to the MFP 10A at T224. Thereafter, processes similar to those from T226 to T252 are executed between the MFPs 10A and 10B and the terminal device 100. Then, MFP 10A identifies public key PK1 associated with user ID "U1" in user table 38A, and decrypts signature information SI1 in the authentication response using the identified public key PK1 in T254. After that, processes similar to those in T260 to T294 are executed between MFPs 10A, 10B, and terminal device 100.

[0094] (Ninth Modification) The "first function executing device," "second function executing device," and "third function executing device" are not limited to MFPs 10A, 10B, and 10C, and may be, for example, a printer, a scanner, a PC, or the like.

[0095] (Tenth Modification) In the above embodiment, the processes of FIGS. 3 to 8 are realized by software (for example, programs 36A to 36C), but at least one of these processes may be realized by hardware such as a logic circuit.

[0096] Furthermore, the technical elements described in this specification or drawings may exhibit technical utility either alone or in various combinations, and are not limited to the combinations described in the claims at the time of filing. Furthermore, the technologies illustrated in this specification or drawings simultaneously achieve multiple objectives, and achieving one of those objectives is itself technically useful. The following is a description corresponding to the claims at the time of filing. (Item 1) 1. A communication system comprising: a first function performing device; and a second function performing device operable according to a predetermined authentication scheme utilizing a pair of keys, the second function performing device being different from the first function performing device, the first function performing device, a result information request sending unit that, when a first function execution instruction is given from a target user to the first function performing device, sends to the second function performing device a result information request requesting transmission of result information indicating that authentication of the target user has been successful; the second function performing device, a first verification information transmitting unit that transmits first verification information to the terminal device when access to the second function performing device from a terminal device operable according to the predetermined authentication method is accepted in response to the first function performing instruction being given to the first function performing device, wherein the terminal device receives the first verification information from the second function performing device, and when first authentication of the target user performed by the terminal device is successful, the first verification information transmitting unit generates first signature information by encrypting the first verification information using a private key of the pair of keys and transmits the first signature information to the second function performing device; a first decryption unit that, when the first signature information is received from the terminal device in response to transmitting the first verification information to the terminal device, decrypts the first signature information by using a public key of the pair of keys; a result information request receiving unit that receives the result information request from the first function performing device; a result information transmitting unit configured to transmit the result information to the first function performing device when the first verification information is obtained by decrypting the first signature information and the result information request is received from the first function performing device; the first function performing device, a first function executing unit that executes a first function when the result information is received from the second function executing device; the second function performing device, a second verification information transmitting unit that transmits second verification information to the terminal device when a second function execution instruction is given from the target user to the second function performing device and the terminal device accepts access to the second function performing device, wherein the terminal device receives the second verification information from the second function performing device, and when a second authentication of the target user performed by the terminal device is successful, the second verification information transmitting unit generates second signature information by encrypting the second verification information using the private key and transmits the second signature information to the second function performing device; a second decryption unit that decrypts the second signature information by using the public key when the second signature information is received from the terminal device; a second function execution unit that executes a second function when the second verification information is obtained by decrypting the second signature information; A communication system comprising: (Item 2) a first function performing device, a result information request sending unit that, when a first function executing instruction is given from a target user to the first function performing device, sends a result information request to a second function performing device to request transmission of result information indicating that authentication of the target user has been successful, the second function performing device being operable according to a predetermined authentication method that uses a pair of keys; a function executing unit that executes a first function when the result information is received from the second function executing device; A terminal device that is operable in accordance with the predetermined authentication method, accessing the second function performing device in response to the first function performing instruction being given to the first function performing device, and receiving first verification information from the second function performing device; If a first authentication of the target user performed by the terminal device is successful, generating first signature information by encrypting the first verification information using a private key of the pair of keys; transmitting the first signature information to the second function performing device; the second function performing device, When the first signature information is received from the terminal device, the first signature information is decrypted using the public key of the pair of keys; When the first verification information is obtained by decrypting the first signature information and the result information request is received from the first function performing device, sending the result information to the first function performing device; The terminal device further receiving second verification information from the second function performing device when a second function performing instruction is given from the target user to the second function performing device and the target user accesses the second function performing device; If a second authentication of the target user performed by the terminal device is successful, generating second signature information by encrypting the second verification information using the private key; transmitting the second signature information to the second function performing device; The second function execution device further comprises: When the second signature information is received from the terminal device, the second signature information is decrypted using the public key; performing a second function if the second verification information is obtained by decrypting the second signature information; A first function performing unit. (Item 3) the first function performing device is a device capable of performing at least one of a printing function and a scanning function, 3. The first function executing device according to item 2, wherein the first function is the at least one of the functions. (Item 4) the first function is a web server function that uses a web server in the first function executing device, The first function performing device further comprises: 4. The first function executing device according to item 2 or 3, further comprising a token sending unit that sends a token to the terminal device for communication with the first function executing device when the result information is received from the second function executing device. (Item 5) 5. The first function executing device according to any one of items 2 to 4, wherein the result information request sending unit sends the result information request to the second function executing device when receiving the first function executing instruction from the terminal device. (Item 6) The predetermined authentication method is FIDO (Fast Identity Online 6. The first function performing device according to any one of items 2 to 5, which is an authentication method. (Item 7) The first function performing device further comprises: 7. The first function executing device according to any one of items 2 to 6, further comprising: a location information transmitting unit that transmits location information of the second function executing device to the terminal device when the first function executing instruction is given from the target user to the first function executing device, and the terminal device accesses the second function executing device using the location information when the location information is received from the first function executing device. (Item 8) 8. The first function performing device according to item 7, wherein the result information request sending unit sends the result information request to the second function performing device after sending the location information to the terminal device. (Item 9) a second function performing device operable according to a predetermined authentication scheme utilizing a pair of keys, a first verification information transmitting unit configured to transmit first verification information to a terminal device operable according to the predetermined authentication method in response to a first function executing instruction being given from a target user to a first function executing device different from the second function executing device, when access to the second function executing device from the terminal device operable according to the predetermined authentication method is accepted, the first function performing device, in response to the first function performing instruction being given from the target user to the first function performing device, transmits to the second function performing device a result information request requesting transmission of result information indicating that authentication of the target user has been successful; the terminal device receives the first verification information from the second function performing device, and when a first authentication of the target user performed by the terminal device is successful, generates first signature information by encrypting the first verification information using a private key of the pair of keys, and transmits the first signature information to the second function performing device. the first verification information transmission unit; a first decryption unit that, when the first signature information is received from the terminal device in response to transmitting the first verification information to the terminal device, decrypts the first signature information by using a public key of the pair of keys; a result information request receiving unit that receives the result information request from the first function performing device; a result information transmitting unit configured to transmit the result information to the first function performing device when the first verification information is obtained by decrypting the first signature information and the result information request is received from the first function performing device, the first function performing device executing the first function when the result information is received from the second function performing device; a second verification information transmitting unit configured to transmit second verification information to the terminal device when a second function execution instruction is given from the target user to the second function performing device and the terminal device accepts access to the second function performing device, the terminal device receives the second verification information from the second function performing device, and when a second authentication of the target user performed by the terminal device is successful, generates second signature information by encrypting the second verification information using the private key, and transmits the second signature information to the second function performing device. the second verification information transmission unit; a second decryption unit that decrypts the second signature information by using the public key when the second signature information is received from the terminal device; a function execution unit that executes a second function when the second verification information is obtained by decrypting the second signature information; A second function performing device comprising: (Item 10) A communication system comprising: a first function performing device; a second function performing device operable according to a predetermined authentication method using a pair of keys and different from the first function performing device; and a third function performing device different from the first function performing device and the second function performing device, the first function performing device, a first result information request sending unit that, when a first function execution instruction is given from a target user to the first function performing device, sends to the second function performing device a first result information request requesting transmission of first result information indicating that authentication of the target user has been successful; the second function performing device, a first verification information transmitting unit that transmits first verification information to the terminal device when access to the second function performing device from a terminal device operable according to the predetermined authentication method is accepted in response to the first function performing instruction being given to the first function performing device, wherein the terminal device receives the first verification information from the second function performing device, and when first authentication of the target user performed by the terminal device is successful, the first verification information transmitting unit generates first signature information by encrypting the first verification information using a private key of the pair of keys and transmits the first signature information to the second function performing device; a first decryption unit that, when the first signature information is received from the terminal device in response to transmitting the first verification information to the terminal device, decrypts the first signature information by using a public key of the pair of keys; a first result information request receiving unit that receives the first result information request from the first function performing device; a first result information transmitting unit that transmits the first result information to the first function performing device when the first verification information is obtained by decrypting the first signature information and the first result information request is received from the first function performing device; the first function performing device, a first function executing unit that executes a first function when the first result information is received from the second function executing device; the third function performing device, a second result information request sending unit that, when a second function execution instruction is given from the target user to the third function performing device, sends to the second function performing device a second result information request requesting transmission of second result information indicating that authentication of the target user has been successful; the second function performing device, a second verification information transmitting unit that transmits second verification information to the terminal device when the terminal device accepts access to the second function performing device in response to the second function performing instruction being given to the third function performing device, wherein the terminal device receives the second verification information from the second function performing device, and when second authentication of the target user performed by the terminal device is successful, the second verification information transmitting unit generates second signature information by encrypting the second verification information using the private key and transmits the second signature information to the second function performing device; a second decryption unit that, when the second signature information is received from the terminal device in response to transmitting the second verification information to the terminal device, decrypts the second signature information by using the public key; a second result information request receiving unit that receives the second result information request from the third function performing device; a second result information transmitting unit configured to transmit the second result information to the third function performing device when the second verification information is obtained by decrypting the second signature information and the second result information request is received from the third function performing device; the third function performing device, a second function executing unit that executes a second function when the second result information is received from the second function executing device; A communication system comprising: (Item 11) a first function performing device, a result information request sending unit that, when a first function execution instruction is given from a target user to the first function performing device, sends a first result information request to a second function performing device, the result information request requesting transmission of first result information indicating that authentication of the target user has been successful, the second function performing device being operable according to a predetermined authentication method that uses a pair of keys; a function executing unit that executes a first function when the first result information is received from the second function executing device; A terminal device that is operable in accordance with the predetermined authentication method, accessing the second function performing device in response to the first function performing instruction being given to the first function performing device, and receiving first verification information from the second function performing device; If a first authentication of the target user performed by the terminal device is successful, generating first signature information by encrypting the first verification information using a private key of the pair of keys; transmitting the first signature information to the second function performing device; the second function performing device, When the first signature information is received from the terminal device, the first signature information is decrypted using the public key of the pair of keys; When the first verification information is obtained by decrypting the first signature information and the first result information request is received from the first function performing device, sending the first result information to the first function performing device; a third function performing device different from the first and second function performing devices; when a second function execution instruction is given from the target user to the third function performing device, transmitting a second result information request to the second function performing device, the second result information request requesting transmission of second result information indicating that authentication of the target user has been successful; The terminal device further accessing the second function performing device in response to the second function performing instruction being given to the third function performing device, and receiving second verification information from the second function performing device; If a second authentication of the target user performed by the terminal device is successful, generating second signature information by encrypting the second verification information using the private key; transmitting the second signature information to the second function performing device; The second function execution device further comprises: When the second signature information is received from the terminal device, the second signature information is decrypted using the public key; When the second verification information is obtained by decrypting the second signature information and the second result information request is received from the third function performing device, sending the second result information to the third function performing device; The third function execution device further comprises: executing a second function when the second result information is received from the second function performing device; A first function performing unit. (Item 12) the first function performing device is a device capable of performing at least one of a printing function and a scanning function, Item 12. The first function executing device according to item 11, wherein the first function is the at least one of the functions. (Item 13) the first function is a web server function that uses a web server in the first function executing device, The first function performing device further comprises: Item 13. The first function executing device according to item 11 or 12, further comprising a token sending unit that sends a token to the terminal device for communication with the first function executing device when the first result information is received from the second function executing device. (Item 14) 14. The first function executing device according to any one of items 11 to 13, wherein the result information request sending unit sends the first result information request to the second function executing device when receiving the first function executing instruction from the terminal device. (Item 15) The predetermined authentication method is FIDO (Fast Identity Online 15. The first function performing device according to any one of items 11 to 14, wherein the first function performing device is an authentication method. (Item 16) The first function performing device further comprises: 16. The first function executing device according to any one of items 11 to 15, further comprising: a location information transmitting unit that transmits location information of the second function executing device to the terminal device when the first function executing instruction is given from the target user to the first function executing device, and the terminal device accesses the second function executing device using the location information when the location information is received from the first function executing device. (Item 17) Item 17. The first function performing device according to item 16, wherein the result information request sending unit sends the first result information request to the second function performing device after sending the location information to the terminal device. (Item 18) a second function performing device operable according to a predetermined authentication scheme utilizing a pair of keys, a first verification information transmitting unit configured to transmit first verification information to a terminal device operable according to the predetermined authentication method in response to a first function executing instruction being given from a target user to a first function executing device different from the second function executing device, when access to the second function executing device from the terminal device operable according to the predetermined authentication method is accepted, the first function performing device, In response to the first function executing instruction being given to the first function executing device, transmitting a first result information request to the second function executing device, the first result information request requesting transmission of first result information indicating that authentication of the target user has been successful; The terminal device receiving the first verification information from the second function performing device and, when a first authentication of the target user performed by the terminal device is successful, generating first signature information by encrypting the first verification information using a private key of the pair of keys; transmitting the first signature information to the second function performing device; the first verification information transmission unit; a first decryption unit that, when the first signature information is received from the terminal device in response to transmitting the first verification information to the terminal device, decrypts the first signature information by using a public key of the pair of keys; a first result information request receiving unit that receives the first result information request from the first function performing device; a first result information transmitting unit that transmits the first result information to the first function performing device when the first verification information is obtained by decrypting the first signature information and the first result information request is received from the first function performing device, and the first function performing device executes a first function when the first result information is received from the second function performing device; a second verification information transmitting unit configured to transmit second verification information to the terminal device when the terminal device accepts access to the second function performing device in response to a second function performing instruction being given from the target user to a third function performing device different from the first function performing device and the second function performing device, the third function performing device, In response to the second function executing instruction being given to the third function executing device, transmitting a second result information request to the second function executing device, the second result information requesting transmission of second result information indicating that authentication of the target user has been successful; The terminal device receiving the first verification information from the second function performing device and, if a second authentication of the target user performed by the terminal device is successful, generating second signature information by encrypting the second verification information using the private key; transmitting the second signature information to the second function performing device; the second verification information transmission unit; a second decryption unit that, when the second signature information is received from the terminal device in response to transmitting the second verification information to the terminal device, decrypts the second signature information by using the public key; a second result information request receiving unit that receives the second result information request from the third function performing device; a second result information transmitting unit that transmits the second result information to the third function performing device when the second verification information is obtained by decrypting the second signature information and the second result information request is received from the third function performing device, and the third function performing device executes the second function when the second result information is received from the second function performing device; A second function performing device comprising: (Item 19) The second function execution device further comprises: a first authentication acceptance request receiving unit that receives a first authentication acceptance request from the first function performing device, the first authentication acceptance request being transmitted from the first function performing device to the second function performing device in response to a third function performing instruction being given by the target user, the third function performing instruction being an instruction to cause the first function performing device and the third function performing device to perform a third function; a third result information receiving unit that receives, after the first authentication acceptance request is received from the first function performing device, a third result information request for sending third result information indicating that the authentication of the target user has been successful, from the first function performing device; a second authentication acceptance request receiving unit that receives a second authentication acceptance request from the third function performing device, the second authentication acceptance request being transmitted from the third function performing device to the second function performing device in response to the third function performing instruction being given by the target user; a fourth result information receiving unit that receives, after the second authentication acceptance request is received from the third function performing device, a fourth result information request for sending fourth result information indicating that the authentication of the target user has been successful, from the third function performing device; a third verification information transmitting unit that transmits third verification information to the terminal device when the terminal device accepts access to the second function performing device after receiving the first authentication acceptance request from the first function performing device and the second authentication acceptance request from the third function performing device, wherein the terminal device receives the third verification information from the second function performing device and, when a third authentication of the target user performed by the terminal device is successful, encrypts the third verification information using the private key to generate third signature information and transmits the third signature information to the second function performing device; a third decryption unit that, when the third signature information is received from the terminal device in response to transmitting the third verification information to the terminal device, decrypts the third signature information by using the public key; a third result information transmitting unit that transmits the third result information to the first function performing device when the third verification information is obtained by decrypting the third signature information and the third result information request is received from the first function performing device, and the first function performing device executes the third function when the third result information is received from the second function performing device; a fourth result information transmitting unit that transmits the fourth result information to the third function performing device when the third verification information is obtained by decrypting the third signature information and the fourth result information request is received from the third function performing device, and the third function performing device executes the third function when the fourth result information is received from the second function performing device; Item 19. The second function performing device according to item 18, comprising: [Explanation of symbols]

[0097] 2: Communication system, 4: LAN, 10A to 10C: MFP, 12: Operation unit, 14: Display unit, 16: Print execution unit, 18: Scan execution unit, 20: Communication I / F, 30: Control unit, 32: CPU, 34A to 34C: Memory, 36A to 36C: Program, 38A to 38C: User table, 40B, 40C: FIDO information, 100: Terminal device, 112: Operation unit, 114: Display unit, 120: Communication I / F, 130: Control unit, 132: CPU, 134: Memory, 138: Fingerprint information, 140: Bulk setting application, 200: PC

Claims

1. A communication system comprising: a first function performing device; a second function performing device operable according to a predetermined authentication method using a pair of keys and different from the first function performing device; and a third function performing device different from the first function performing device and the second function performing device, the first function performing device, a first result information request sending unit that, when a first function execution instruction is given from a target user to the first function performing device, sends to the second function performing device a first result information request requesting transmission of first result information indicating that authentication of the target user has been successful; the second function performing device, a first verification information transmitting unit that, in response to the first function executing instruction being given to the first function performing device, transmits first verification information to the terminal device when accepting access to the second function performing device from a terminal device operable according to the predetermined authentication method, wherein the terminal device receives the first verification information from the second function performing device, and, when first authentication of the target user performed by the terminal device is successful, generates first signature information by encrypting the first verification information using a private key of the pair of keys and transmits the first signature information to the second function performing device; a first decryption unit that, when the first signature information is received from the terminal device in response to transmitting the first verification information to the terminal device, decrypts the first signature information by using a public key of the pair of keys; a first result information request receiving unit that receives the first result information request from the first function performing device; a first result information transmitting unit configured to transmit the first result information to the first function performing device when the first verification information is obtained by decrypting the first signature information and the first result information request is received from the first function performing device; the first function performing device, a first function executing unit that executes a first function when the first result information is received from the second function executing device; the third function performing device, a second result information request sending unit that, when a second function execution instruction is given from the target user to the third function performing device, sends to the second function performing device a second result information request requesting transmission of second result information indicating that authentication of the target user has been successful; the second function performing device, a second verification information transmitting unit that transmits second verification information to the terminal device when the terminal device accepts access to the second function performing device in response to the second function performing instruction being given to the third function performing device, wherein the terminal device receives the second verification information from the second function performing device, and when second authentication of the target user performed by the terminal device is successful, the second verification information transmitting unit generates second signature information by encrypting the second verification information using the private key and transmits the second signature information to the second function performing device; a second decryption unit that, when the second signature information is received from the terminal device in response to transmitting the second verification information to the terminal device, decrypts the second signature information by using the public key; a second result information request receiving unit that receives the second result information request from the third function performing device; a second result information transmitting unit configured to transmit the second result information to the third function performing device when the second verification information is obtained by decrypting the second signature information and the second result information request is received from the third function performing device; the third function performing device, a second function executing unit that executes a second function when the second result information is received from the second function executing device; A communication system comprising:

2. the first function performing device is a device capable of performing at least one of a printing function and a scanning function, The communication system according to claim 1 , wherein the first function is the at least one function.

3. the first function is a web server function that utilizes a web server in the first function executing device, The first function performing device further comprises:

3. The communication system according to claim 1, further comprising: a token transmitting unit configured to transmit, to the terminal device, a token for the terminal device to communicate with the first function performing device when the first result information is received from the second function performing device.

4. 4. The communication system according to claim 1, wherein the first result information request sending unit sends the first result information request to the second function executing device when the first function executing instruction is received from the terminal device.

5. The communication system according to claim 1 , wherein the predetermined authentication method is an FIDO (short for Fast Identity Online) authentication method.

6. The first function performing device further comprises:

6. The communication system according to claim 1, further comprising: a location information transmitting unit configured to transmit location information of the second function executing device to the terminal device when the first function executing instruction is given from the target user to the first function executing device, wherein the terminal device accesses the second function executing device using the location information when the location information is received from the first function executing device.

7. The communication system according to claim 6 , wherein the first result information request transmitting unit transmits the first result information request to the second function performing device after transmitting the location information to the terminal device.

8. The first function execution device further comprises: a first authentication acceptance request sending unit that sends a first authentication acceptance request to the second function performing device when a third function execution instruction, which is an instruction to cause the first function performing device and the third function performing device to perform a third function, is given from the target user; The second function performing device further comprises: a first authentication acceptance request receiving unit that receives the first authentication acceptance request from the first function performing device; The first function performing device further comprises: a third result information request sending unit that sends, after the first authentication acceptance request is sent to the second function performing device, a third result information request that requests the second function performing device to send third result information indicating that the authentication of the target user has been successful; The second function performing device further comprises: a third result information request receiving unit that receives the third result information request from the first function performing device after the first authentication acceptance request is received from the first function performing device; The third function performing device further comprises: a second authentication acceptance request sending unit that sends a second authentication acceptance request to the second function performing device when the third function performing instruction is given by the target user; The second function performing device further comprises: a second authentication acceptance request receiving unit that receives the second authentication acceptance request from the third function performing device; The third function performing device further comprises: a fourth result information request sending unit that sends, after the second authentication acceptance request is sent to the second function performing device, a fourth result information request that requests the second function performing device to send fourth result information indicating that the authentication of the target user has been successful; The second function performing device further comprises: a fourth result request information receiving unit that receives the fourth result information request from the third function performing device after the second authentication acceptance request is received from the third function performing device; a third verification information transmitting unit that transmits third verification information to the terminal device when the terminal device accepts access to the second function performing device after receiving the first authentication acceptance request from the first function performing device and the second authentication acceptance request from the third function performing device, wherein the terminal device receives the third verification information from the second function performing device and, when a third authentication of the target user performed by the terminal device is successful, encrypts the third verification information using the private key to generate third signature information and transmits the third signature information to the second function performing device; a third decryption unit that, when the third signature information is received from the terminal device in response to transmitting the third verification information to the terminal device, decrypts the third signature information by using the public key; a third result information transmitting unit that transmits the third result information to the first function performing device when the third verification information is obtained by decrypting the third signature information and the third result information request is received from the first function performing device; a fourth result information transmitting unit that transmits the fourth result information to the third function performing device when the third verification information is obtained by decrypting the third signature information and the fourth result information request is received from the third function performing device; Equipped with The first function performing device further comprises: a third result information receiving unit that receives the third result information from the second function executing device; a third function executing unit that executes the third function when the third result information is received from the second function executing device; The third function performing device further comprises: a fourth result information receiving unit that receives the fourth result information from the second function performing device; The communication system according to claim 7 , further comprising: a fourth function executing unit that executes the third function when the fourth result information is received from the second function executing device.

Citation Information

Patent Citations

  • Information processing device, control method of the same, and program

    JP2015158805A

  • Image processing system and method and program and system

    JP2018205906A

  • Image processing device, image processing device control method, program, system and system control method

    JP2019086937A

  • Image forming apparatus, printing system, image forming apparatus control method, and program

    JP2019212094A