Information processing system, authentication method, program, and device

The information processing system facilitates guest user access by pre-registering account information, allowing temporary users to log in and use devices with restricted functions, addressing the challenge of account-less user authentication.

JP7771614B2Active Publication Date: 2025-11-18RICOH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2021166249
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-10-08
Publication Date
2025-11-18
Estimated Expiration
2041-10-08

AI Technical Summary

Technical Problem

Conventional authentication systems prevent temporary users without accounts from logging in to devices or systems.

Method used

An information processing system that allows temporary users to log in by pre-registering account information for guest users, enabling authentication through an authentication server using a guest login button, which requests and uses account information stored in the system.

Benefits of technology

Enables temporary users to access devices without prior account information, while allowing system administrators to restrict device functions and manage guest user access effectively.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007771614000001
    Figure 0007771614000001
  • Figure 0007771614000002
    Figure 0007771614000002
  • Figure 0007771614000003
    Figure 0007771614000003
Patent Text Reader

Abstract

To provide an information processing system in which temporary users who do not have their accounts can log in.SOLUTION: The present invention is an information processing system 100 in which an information processing device 10 and an apparatus 20 communicate via a network. The apparatus includes an authentication control unit that requests account information from the information processing device when a predetermined operation is received, and the information processing device includes a communication unit that transmits the account information to the apparatus. The authentication control unit designates the account information received from the information processing device, requests authentication from an authentication server 40, and acquires an authentication result.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an information processing system, an authentication method, a program, and a device. [Background technology]

[0002] When a user uses a device such as an image forming device, they may be required to log in. Logging in refers to the act of authenticating the user to access the resources of the device or the system to which the device is connected using pre-registered account information when using various computer or internet services.

[0003] A technology has been devised to perform such authentication on a server (see, for example, Patent Document 1). Patent Document 1 discloses a device that acquires authentication screen data from an information processing device and displays it, transmits input information entered by a user on the displayed authentication screen to the information processing device, and acquires an authentication result based on the input information. Summary of the Invention [Problem to be solved by the invention]

[0004] However, conventional techniques have had the problem that temporary users who do not have an account cannot log in.

[0005] In view of the above-mentioned problems, an object of the present invention is to provide an information processing system that allows temporary users who do not have accounts to log in. [Means for solving the problem]

[0006] In view of the above problems, the present invention provides an information processing device, Ne via the network the information processing device; Communicate equipment, including An information processing system, the information processing device includes a setting receiving unit that transmits screen information of a guest login setting screen that receives settings related to temporary users to a terminal device that can communicate with the information processing device via a network, receives settings of account information from the terminal device, and stores the received account information in the information processing device; a communication unit that requests an authentication server to store the account information; When the device receives a predetermined operation, The aforementionedan authentication control unit that requests account information from the information processing device; The communication unit Send the account information to the device Faith The authentication control unit specifies the account information received from the information processing device The aforementioned It is characterized by requesting authentication from an authentication server and obtaining the authentication result. [Effects of the Invention]

[0007] It is possible to provide an information processing system that allows temporary users who do not have an account to log in. [Brief explanation of the drawings]

[0008] [Figure 1] FIG. 2 is a diagram illustrating an overview of an authentication method performed by the information processing system. [Figure 2] 1 is a diagram illustrating a system configuration of an example of an information processing system according to an embodiment of the present invention. [Figure 3] FIG. 2 is a diagram illustrating an example of a hardware configuration of an information processing device and a terminal device. [Figure 4] FIG. 2 is a diagram illustrating a hardware configuration of an example of a device. [Figure 5] FIG. 2 is a diagram illustrating an example of a software configuration of a device. [Figure 6] FIG. 1 is a diagram illustrating a functional configuration of an example of an information processing system. [Figure 7] FIG. 10 is a diagram illustrating an example of on-premise account information held by a management unit. [Figure 8] FIG. 10 is a diagram illustrating an example of guest login permitted device information managed by a management unit. [Figure 9] FIG. 4 is a diagram showing an example of account information stored in an account information storage unit. [Figure 10] FIG. 2 is a diagram showing an example of usage restriction information stored in a usage restriction information storage unit. [Figure 11] FIG. 10 is a sequence diagram illustrating an example of a process in which an administrator registers account information and the like of a guest user. [Figure 12]FIG. 10 is a diagram illustrating an example of a guest login setting screen. [Figure 13] FIG. 10 is a diagram illustrating an example of a usage restriction setting screen. [Figure 14] FIG. 10 is a sequence diagram illustrating an example of a process for a guest user to log in to a device. [Figure 15] FIG. 10 is a diagram illustrating an example of a login screen displayed by the device. DETAILED DESCRIPTION OF THE INVENTION

[0009] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS An information processing system and an authentication method performed by the information processing system will be described below as an example of an embodiment of the present invention with reference to the accompanying drawings.

[0010] <Outline of operation> FIG. 1 is a diagram illustrating an overview of an authentication method performed by an information processing system 100. As shown in FIG.

[0011] (1) When the administrator A inputs the account information of the guest user on a guest login setting screen (described later), the information processing device 10 holds an account for the guest user. The information processing device 10 registers the account information of the guest user in the authentication server 40.

[0012] (2) An authentication application runs on device 20, such as an image forming device. Guest user B presses the guest login button displayed by the authentication application. Guest user B does not need to enter account information. Here, the guest login button is an example of an operation component that accepts operations from a user.

[0013] (3) The authentication application acquires the account information of the guest user from the information processing device 10. The account information of the guest user may be common regardless of the guest user.

[0014] (4) The authentication application uses the guest user's account information to send an authentication request to the authentication server 40. If the authentication is successful, guest user B can log in to the device 20.

[0015] In this way, the information processing system 100 of this embodiment allows the guest user B to use the device 20 even if he does not know (enter) his user account information.

[0016] <Terminology> Authentication refers to determining whether a user is a legitimate authorized person. In this embodiment, it refers to whether the user has the authority to use the device. If authentication is successful, the user logs in to the device or to the information processing device 10 via the device.

[0017] The login screen is a screen where a user inputs account information. The login screen may also be called a sign-in screen or an authentication screen. Account information is information used for authentication. Anyone who knows the account information is presumed to be a legitimate authorized person. Account information is a set of multiple pieces of information, such as "email address and password" or "tenant ID, user ID, and password," but in this embodiment, information equivalent to a password is the account information.

[0018] The administrator is a system administrator or the like on the customer side who uses the information processing system 100, and is a person who performs settings related to the information processing system 100 for general users.

[0019] A guest user is a user who temporarily uses the device 20. A guest user is also called a temporary user. A general user is a user who uses the device 20 on a continuous basis, such as an employee of a client company. When there is no need to distinguish between guest users and general users, they are simply called users.

[0020] <System configuration example> The system configuration of the information processing system 100 according to this embodiment will be described with reference to Fig. 2. Fig. 2 is a diagram showing an example of the system configuration of the information processing system 100 according to this embodiment.

[0021] 2 includes an information processing device 10 and a device 20, which are communicably connected via a wide area network N such as the Internet. The information processing device 10 can also communicate with various authentication servers 40 and terminal devices 60.

[0022] The information processing device 10 is realized by one or more computers, and provides various services to users via a network N, either alone or in cooperation with an authentication server 40. The information processing device 10 according to this embodiment provides a wide range of services, including, for example, a workflow service that executes a series of processes such as scanning a document, OCR of image data, and uploading a file. Another example of a service is pull printing, in which a device 20 downloads a file from a storage service and prints it. In addition, the information processing device 10 can provide various other services using the device 20.

[0023] The information processing device 10 has a function to authenticate a user who uses the device 20. The user can be authenticated by the information processing device 10 or by the authentication server 40. The administrator can set in advance which method to use for authentication (included in the authentication method settings). In this embodiment, a case where authentication is performed by the authentication server 40 will be described.

[0024] The information processing device 10 may be realized by cloud computing, or may be realized by a single information processing device 10. Cloud computing refers to a form in which resources on a network are used without being aware of specific hardware resources. The information processing device 10 may exist on the Internet or on-premise.

[0025] The device 20 is any of various electronic devices used by a user. The device 20 is, for example, an image forming device such as an MFP (Multifunction Peripheral), a projector, an electronic whiteboard, a video conference terminal, a digital camera, etc. In addition, the device 20 may have a web browser or equivalent functionality. The device 20 can communicate with the information processing device 10 or the authentication server 40 via the network N. The user can use the device 20 to utilize various services provided by the information processing device 10 or the authentication server 40.

[0026] There may be multiple authentication servers 40 depending on the function. The authentication server 40 may be managed by the same operator as the operator of the information processing device 10, or may be managed by a different service operator than the information processing device 10. There may be multiple authentication servers 40, and when distinguishing between the individual authentication servers 40, they will be referred to as authentication servers 40A, 40B, and any authentication server 40 will be simply referred to as "authentication server 40." The authentication server 40 is one or more computers.

[0027] Each authentication server 40 has a function to authenticate users. The authentication server 40 supports, for example, OAUTH. OAUTH is a mechanism for linking and operating multiple web services. Normally, a user needs to enter a user ID and password individually to use a web service, but by using OAUTH, web services (information processing device 10 and authentication server 40) can be linked together without the user having to enter an ID or password individually. When OAUTH is used, the information processing device 10 redirects the device 20 to the authentication server 40, and the authentication server 40 authenticates the user.

[0028] The terminal device 60 is a general-purpose computer that communicates with the information processing device 10. A web browser runs on the terminal device 60 and displays various screens based on screen information received from the information processing device 10. The administrator can use the screen to configure settings related to, for example, the account information of guest users.

[0029] The terminal device 60 may be, for example, a PC (Personal Computer), a smartphone, a tablet terminal, a PDA (Personal Digital Assistant), or the like, as long as it can run a web browser. Note that the terminal device 60 is not limited to a web browser, and a dedicated application for the information processing device 10 may also run.

[0030] <Hardware configuration example> The hardware configurations of the information processing device 10 and the device 20 included in the information processing system 100 according to this embodiment will be described with reference to FIGS.

[0031] <<Information processing devices, terminal devices>> 3 is a diagram showing an example of the hardware configuration of the information processing device 10 and the terminal device 60 according to this embodiment. The hardware configuration of the authentication server 40 may be the same as that shown in FIG. 3, or may be different without hindering the description of this embodiment.

[0032] 3, the information processing device 10 and the terminal device 60 are configured by a computer 500. The computer 500 includes a CPU 501, a ROM 502, a RAM 503, a hard disk (HD) 504, a hard disk drive (HDD) controller 505, a display 506, an external device connection interface (I / F) 508, a network I / F 509, a bus line 510, a keyboard 511, a pointing device 512, a digital versatile disk rewritable (DVD-RW) drive 514, and a media I / F 516.

[0033] Of these, the CPU 501 controls the overall operation of the computer 500. The ROM 502 stores programs used to drive the CPU 501, such as the IPL. The RAM 503 is used as a work area for the CPU 501. The HD 504 stores various data, such as programs. The HDD controller 505 controls the reading and writing of various data from and to the HD 504 under the control of the CPU 501. The display 506 displays various information, such as a cursor, menus, windows, characters, or images. The external device connection I / F 508 is an interface for connecting various external devices. In this case, external devices include, for example, USB (Universal Serial Bus) memory and printers. The network I / F 509 is an interface for data communication using the network N. The bus line 510 is an address bus, a data bus, or the like, for electrically connecting the components, such as the CPU 501, shown in FIG. 3.

[0034] The keyboard 511 is a type of input means having multiple keys used to input characters, numbers, various instructions, etc. The pointing device 512 is a type of input means for selecting and executing various instructions, selecting a processing target, moving a cursor, etc. The optical drive 514 controls reading and writing of various data from an optical storage medium 513, which is an example of a removable storage medium. The optical storage medium is a CD, a DVD, Blu-Ray (registered trademark), etc. The media I / F 516 controls reading and writing (storing) of data from a storage medium 515, such as a flash memory.

[0035] <<Equipment>> 4 is a hardware configuration diagram of an image forming apparatus, which is an example of device 20. As shown in FIG. 4, the image forming apparatus includes a controller 910, a short-range communication circuit 920, an engine control unit 930, an operation panel 940, and a network I / F 950.

[0036] Of these, the controller 910 has a CPU 901, which is the main part of the computer, a system memory (MEM-P) 902, a north bridge (NB) 903, a south bridge (SB) 904, an ASIC (Application Specific Integrated Circuit) 906, a local memory (MEM-C) 907, which is a storage unit, an HDD controller 908, and an HD 909, which is also a storage unit, and is configured such that the NB 903 and the ASIC 906 are connected by an AGP (Accelerated Graphics Port) bus 921.

[0037] Of these, the CPU 901 is a control unit that performs overall control of the image forming apparatus. The NB 903 is a bridge that connects the CPU 901 with the MEM-P 902, the SB 904, and the AGP bus 921, and includes a memory controller that controls reading and writing to the MEM-P 902, a PCI (Peripheral Component Interconnect) master, and an AGP target.

[0038] The MEM-P 902 comprises a ROM 902a, which is memory for storing programs and data that realize the functions of the controller 910, and a RAM 902b, which is used for expanding the programs and data and as a drawing memory during memory printing. The programs stored in the RAM 902b may be provided by being recorded in an installable or executable file format on a computer-readable recording medium such as a CD-ROM, CD-R, or DVD.

[0039] The SB 904 is a bridge connecting the NB 903 with PCI devices and peripheral devices. The ASIC 906 is an integrated circuit (IC) for image processing applications that has hardware elements for image processing and acts as a bridge connecting the AGP bus 921, PCI bus 922, HDD controller 908, and MEM-C 907. The ASIC 906 includes a PCI target and AGP master, an arbiter (ARB) that forms the core of the ASIC 906, a memory controller that controls the MEM-C 907, multiple direct memory access controllers (DMACs) that perform image data rotation using hardware logic, and a PCI unit that transfers data between the scanner unit 931, printer unit 932, and facsimile unit via the PCI bus 922. The ASIC 906 may also have a universal serial bus (USB) interface or an IEEE 1394 (Institute of Electrical and Electronics Engineers) interface.

[0040] The MEM-C907 is a local memory used as an image buffer for copying and a code buffer. The HD909 is a storage for storing image data, font data used during printing, and forms. The HD909 controls the reading and writing of data from and to the HD909 under the control of the CPU901. The AGP bus 921 is a bus interface for a graphics accelerator card proposed to speed up graphics processing, and direct high-throughput access to the MEM-P902 enables the graphics accelerator card to operate at high speed.

[0041] Further, the short-range communication circuit 920 is provided with a short-range communication circuit antenna 920a. The short-range communication circuit 920 is a communication circuit such as NFC or Bluetooth (registered trademark).

[0042] The engine control unit 930 further includes a scanner unit 931, a printer unit 932, and a facsimile unit 933. The operation panel 940 includes a panel display unit 940a, such as a touch panel, that displays current setting values ​​and selection screens and receives input from the operator, as well as hard keys 940b including a numeric keypad that receives setting values ​​for image formation conditions such as density settings and a start key that receives a command to start copying. The controller 910 controls the entire image forming apparatus, and controls, for example, drawing, communication, and input from the operation panel 940. The scanner unit 931 or the printer unit 932 includes an image processing unit that performs error diffusion, gamma conversion, and the like.

[0043] The image forming apparatus allows the user to sequentially switch between the document box function, copy function, printer function, and facsimile function using the application switching key on the operation panel 940. When the user selects the document box function, the image forming apparatus enters document box mode, when the user selects the copy function, the image forming apparatus enters copy mode, when the user selects the printer function, the image forming apparatus enters printer mode, and when the user selects the facsimile mode, the image forming apparatus enters facsimile mode.

[0044] The network I / F 950 is an interface for performing data communication using the network N. The short-range communication circuit 920 and the network I / F 950 are electrically connected to the ASIC 906 via a PCI bus 922.

[0045] <Software configuration> Fig. 5 shows a configuration diagram of software included in the device 20. As shown in Fig. 5, the device 20 has an authentication application 71 that runs on the operation panel 940. The authentication application 71 runs on an OS 73. The OS 73 is, for example, Android (registered trademark), but the type of OS 73 is not important as long as the authentication application 71 can run on it, such as Linux (registered trademark).

[0046] Account information of guest users registered by an administrator is registered in the information processing device 10 and the authentication server 40. The authentication application 71 obtains the account information of the guest user from the information processing device 10 and sends the account information to the authentication server 40, thereby requesting authentication of the guest user. The authentication server 40 performs authentication based on the account information of the guest user. If the authentication is successful, the authentication server 40 notifies the authentication application 71 of this fact, and the guest user is then able to use the device 20.

[0047] <About the function> Next, the functional configuration of the information processing system 100 according to this embodiment will be described with reference to Fig. 6. Fig. 6 is a diagram showing an example of the functional configuration of the information processing system 100 according to this embodiment.

[0048] <<Equipment>> The device 20 has a communication unit 21, a display control unit 22, an operation reception unit 23, and an authentication control unit 24. Each of these functional units of the device 20 is a function or means realized by the CPU 901 shown in FIG. 4 executing instructions included in one or more programs (authentication applications) installed in the device 20.

[0049] The communication unit 21 transmits and receives various information to and from the information processing device 10 or the authentication server 40. In this embodiment, the communication unit 21 requests account information of the guest user from the information processing device 10. In addition, the communication unit 21 designates the account information of the guest user and requests authentication from the authentication server 40.

[0050] The display control unit 22 uses pre-stored display components to display a login screen and the like on the panel display unit 940a.

[0051] The operation reception unit 23 receives various operations from the user on various screens displayed on the panel display unit 940a.

[0052] The authentication control unit 24 controls authentication and communication with the information processing device 10 and the authentication server 40 based on a predetermined procedure for authenticating guest users.

[0053] <<Information processing equipment>> The information processing device 10 has a communication unit 11, a screen generation unit 12, a setting reception unit 13, and a management unit 14. Each of these functional units of the information processing device 10 is a function or means realized by the CPU 501 shown in FIG. 3 executing instructions contained in one or more programs installed in the information processing device 10.

[0054] One or more of the functions of the information processing device 10 may be distributed among multiple information processing devices. Furthermore, the functions of the information processing device 10 and the functions of the authentication server 40 may be located in one information processing device, or some of the functions of the information processing device 10 may be located in the authentication server 40, or some of the functions of the authentication server 40 may be located in the information processing device 10.

[0055] The communication unit 11 transmits and receives various information to and from the device 20, the terminal device 60, and the authentication server 40. In this embodiment, the communication unit 11 transmits the account information of the guest user to the device 20 and the authentication server 40.

[0056] The screen generation unit 12 generates screen information for various settings to be displayed on the terminal device 60. The setting reception unit 13 receives settings related to the guest user's account information transmitted from the terminal device 60. The setting reception unit 13 also stores the guest user's account information in the management unit 14 and transmits it to the authentication server 40.

[0057] The screen information is a program written in HTML, XML, a scripting language, and CSS (Cascading Style Sheet), etc., with the structure of the web page being primarily determined by HTML, the behavior of the web page being determined by the scripting language, and the style of the web page being determined by CSS.

[0058] The management unit 14 manages information related to guest user logins, as will be described with reference to FIG. 7. FIG. 7 shows an example of on-premise account information held by the management unit 14. The on-premise account information is a character string equivalent to a password. The authentication server 40 authenticates guest users using only the on-premise account information (no other information such as a user ID is required). This on-premise account information corresponds to the account information of the guest user.

[0059] Furthermore, the management unit 14 manages guest login permitted device information as will be described with reference to Fig. 8. Fig. 8 is an example of guest login permitted device information managed by the management unit 14. In the guest login permitted device information, whether guest user login is valid or invalid (whether guest users can log in) is set in association with the device number. The device number is identification information for the device 20. Whether a guest login button is displayed on the login screen is controlled depending on whether the guest login permitted device information is valid or invalid.

[0060] <<Authentication Server>> The authentication server 40 has a communication unit 41, an authentication unit 42, a registration processing unit 43, an account information storage unit 48, and a usage restriction information storage unit 49. Each of these functional units of the authentication server 40 is a function or means realized by the CPU 501 shown in Fig. 3 executing instructions contained in one or more programs installed in the authentication server 40. One or more of the functions of the authentication server 40 may be distributed and arranged in multiple information processing devices.

[0061] The communication unit 41 transmits and receives various information to and from the device 20 and the information processing device 10. In this embodiment, the communication unit 41 receives account information of the guest user from the device 20 and the information processing device 10, and transmits an authentication result to the device 20.

[0062] The authentication unit 42 authenticates the user based on the account information. This account information is stored in the account information storage unit 48. The account information storage unit 48 is constructed in the HD 504 shown in FIG. 3, etc. If the authentication request includes information that the guest login button has been pressed, the authentication unit 42 authenticates the user based on only the password.

[0063] The registration processing unit 43 performs processing for registering the use restriction information in the use restriction information storage unit 49 and registering the account information of the guest user in the account information storage unit 48 .

[0064] FIG. 9 shows an example of account information stored in the account information storage unit 48. In the account information storage unit 48, account information of users who use the information processing system 100 is registered in association with user IDs (user identification information). The account information is, for example, a password. However, the authentication unit 42 is not limited to user IDs and passwords, and may also authenticate users using "email address and password," "tenant ID, user ID and password," "IC card," "PIN (Personal Identification Number)," etc.

[0065] If the user is an employee, the account information for each employee is registered in advance. For guest users, the account information for guest users is registered through settings made by the administrator. Because the account information for guest users is the same as the user ID, the same character string (Guest) is registered for the user ID and the account information. This character string (Guest) corresponds to the on-premise account information. For guest users, the authentication server 40 authenticates only the on-premise account information.

[0066] Fig. 10 shows an example of usage restriction information stored in the usage restriction information storage unit 49. Functions whose usage is restricted (or functions whose usage is permitted) in the device 20 are registered in association with on-premise account information in the usage restriction information storage unit 49. In Fig. 10, the following settings are made as an example. Copy: Black and white only Printer: None Fax: Available Scanner: Available Document box: Available In this way, the information processing system 100 can limit the functions that can be used by guest users by using the usage restriction information.

[0067] <<Terminal Device>> The terminal device 60 has a communication unit 61, a display control unit 62, and an operation reception unit 63. Each of these functional units is a function or means realized by the CPU 501 shown in Fig. 3 executing instructions contained in one or more programs installed in the computer 500. Note that this program may be a web browser or dedicated software.

[0068] The communication unit 61 transmits and receives various types of information to and from the information processing device 10. In this embodiment, the communication unit 61 receives various types of screen information and the like from the information processing device 10 and transmits information set by an administrator to the information processing device 10.

[0069] The display control unit 62 interprets screen information of various screens and displays it on the display 506. The operation receiving unit 63 receives various operations on the various screens displayed on the display 506 by the user.

[0070] <Registering guest user account information> Next, a process in which an administrator registers account information and the like of a guest user in the information processing device 10 will be described with reference to Fig. 11. Fig. 11 is an example of a sequence diagram illustrating a process in which an administrator registers account information and the like of a guest user. The administrator mainly performs the following three processes.

[0071] (i) Registering a User ID for a Guest User: The administrator registers a user ID to be assigned to a guest user. The user ID becomes the on-premise account information.

[0072] (ii) Usage restriction settings: The administrator sets restrictions on the functions of the image forming device (copying, scanning, printing, etc.) that are permitted for guest users.

[0073] (iii) Selection of devices 20 for which guest login is permitted: The administrator selects devices 20 for which the guest login function can be used (because there are devices 20 that the administrator wants temporary users to use and devices 20 that the administrator does not want temporary users to use).

[0074] S1: The administrator operates the terminal device 60 to input his / her own account information and logs in to the information processing device 10.

[0075] S2: The administrator inputs an operation to display a guest login setting screen on the terminal device 60. The operation acceptance unit 63 of the terminal device 60 accepts the operation, and the communication unit 61 requests the guest login setting screen from the information processing device 10. The screen generation unit 12 of the information processing device 10 generates the guest login setting screen, and the communication unit 11 transmits screen information of the guest login setting screen to the terminal device 60. As a result, the display control unit 62 of the terminal device 60 displays the guest login setting screen. An example of the guest login setting screen is shown in FIG. 12.

[0076] S3: The administrator enters the user ID of the guest user on the guest login setting screen and presses the save button. The operation acceptance unit 63 of the terminal device 60 accepts the operation. The communication unit 61 transmits the user ID of the guest user to the information processing device 10.

[0077] S4: The communication unit 11 of the information processing device 10 receives the user ID of the guest user, and the setting reception unit 13 transmits a user creation request to the authentication server 40, specifying the user ID (on-premise account information).

[0078] S5: The communication unit 41 of the authentication server 40 receives the user ID and the user creation request, and the registration processing unit 43 registers the user ID and password of the guest user in the account information storage unit 48. The password is the on-premise account information (user ID). The user ID and password have the same value. Since the authentication unit 42 authenticates the user using the on-premise account information, the information must be unique for each user. Therefore, if the user ID is duplicated, the registration processing unit 43 prompts the user to reset it.

[0079] S6: The setting reception unit 13 registers the on-premise account information in the management unit 14. When the registration is complete, the screen generation unit 12 causes the terminal device 60 to display a guest user creation completion dialog.

[0080] S7: Next, in order to restrict (select) the functions available to the guest user, the administrator presses the usage restriction setting button on the guest login setting screen. The operation receiving unit 63 receives the operation.

[0081] S8: As a result, the display control unit 62 displays the usage restriction setting screen. The transition from the guest login setting screen to the usage restriction setting screen may be performed by the information processing device 10 or the terminal device 60. Fig. 13 shows an example of the usage restriction setting screen.

[0082] S9: The administrator presses a radio button associated with each function on the usage restriction setting screen, and then presses the confirmation button. The operation reception unit 63 receives these operations. The communication unit 61 associates the usage restriction information generated in accordance with the pressed radio button with the on-premise account information and transmits it to the authentication server 40.

[0083] S10: The communication unit 41 of the authentication server 40 receives the usage restriction information, and the registration processing unit 43 registers the usage restriction information (see FIG. 10) in the usage restriction information storage unit 49 in association with the on-premise account information.

[0084] S11: When the administrator closes the usage restriction setting screen, the display control unit 62 displays the guest login setting screen again.

[0085] S12: Next, the administrator selects the devices 20 for which the guest login function is to be enabled on the guest login setting screen. The operation accepting unit 63 accepts the selection of the devices 20. The communication unit 61 transmits a list of the devices 20 to the information processing device 10.

[0086] S13: The communication unit 11 of the information processing device 10 receives the list of devices 20, and the setting reception unit 13 stores the list of devices 20 in the management unit 14. The list of devices 20 is a list of device numbers.

[0087] <<Guest login settings screen>> 12 is an example of the guest login setting screen 200. Each item on the guest login setting screen 200 will be described below.

[0088] The user ID field 201 is a field where the administrator enters a user ID. The entered user ID becomes on-premise account information.

[0089] The save button 202 is a button for the terminal device 60 to transmit the user ID to the information processing device 10.

[0090] The usage restriction setting button 203 is a button for displaying a usage restriction setting screen on the terminal device 60.

[0091] The device list field 204 displays a list of devices 20 managed by the information processing device 10. The device list field 204 has a radio button 205 for each device 20, indicating whether it is enabled or disabled. By pressing the radio button 205 for each device 20, the administrator can set whether to permit guest users to log in for each device 20.

[0092] <<Usage restriction setting screen>> 13 is an example of the usage restriction setting screen 210. Each item on the usage restriction setting screen 210 will be described below.

[0093] Copy box 211a The settings for colors that guest users can select when copying are displayed. By pressing radio button 211b, the administrator can set the colors that guest users can select when copying. The administrator can also prohibit copying altogether.

[0094] Printer column 212a The settings for colors that guest users can select when printing are displayed. By pressing radio button 212b, the administrator can set the colors that guest users can select when printing. The administrator can also prohibit printing altogether.

[0095] Fax field 213a The administrator sets whether or not the guest user can use the fax by pressing the radio button 213b.

[0096] Scanner column 214a The administrator sets whether or not the guest user can use the scanner by pressing radio button 214b.

[0097] Document box section 215a The administrator sets whether or not the guest user can use the document box by pressing the radio button 215b.

[0098] <Guest user login> Next, a login process for a guest user will be described with reference to Fig. 14. Fig. 14 is an example of a sequence diagram illustrating a process for a guest user to log in to the device 20.

[0099] S21: When the device 20 starts up, the OS 73 starts up the authentication application 71 and requests the authentication application 71 to display a login screen. Note that, in order for the information set on the guest login setting screen to be reflected on the login screen, the device 20 needs to be restored from an energy saving state, powered on, or the like.

[0100] S22: The authentication application 71 displays a login preparation screen (for example, a "Please wait a moment" screen is displayed).

[0101] S23: The authentication application 71 performs initialization processing. The initialization processing is not directly related to this embodiment, so details thereof will be omitted.

[0102] S24: After startup, the authentication control unit 24 inquires of the information processing device 10 whether the guest login function of its own device 20 is enabled. When making the inquiry, the device number is specified. In addition to the device number, any information that can identify the device 20, such as an authentication ticket, may be used.

[0103] S25: The communication unit 11 of the information processing device 10 receives the inquiry and transmits to the device 20 whether the guest login permission device information is valid or invalid in association with the device number.

[0104] S26: When the communication unit 21 of the device 20 receives the guest login permitted device information (invalid), the display control unit 22 displays a login screen without a guest login button. That is, the device 20 displays a conventional login screen. This prevents the device 20 from displaying the guest login button even when a guest user cannot log in.

[0105] S27: When the communication unit 21 of the device 20 receives the guest login permitted device information (valid), the display control unit 22 displays a login screen with a guest login button. This login screen is shown in FIG.

[0106] S28: The guest user presses the guest login button on the login screen. The operation reception unit 23 receives the press.

[0107] S29: The authentication control unit 24 of the device 20 requests the information processing device 10 via the communication unit 21 for the account information of the guest user.

[0108] S30: The communication unit 11 of the information processing device 10 receives the request for the account information of the guest user, and transmits the on-premise account information acquired from the management unit 14 to the device 20.

[0109] S31: The communication unit 21 of the device 20 receives the on-premise account information. The authentication control unit 24 sends an authentication request to the authentication server 40 via the communication unit 21, indicating that the guest login button has been pressed and specifying the on-premise account information.

[0110] S32: The communication unit 41 of the authentication server 40 receives an authentication request including a notice that the guest login button has been pressed and the on-premise account information, and the authentication unit 42 authenticates the guest user based on the password in the account information storage unit 48. As described above, when the guest login button is pressed, authentication is possible using the on-premise account information (password) alone, and authentication is successful if the on-premise account information (password) is stored in the account information storage unit 48. However, the authentication unit 42 may also perform authentication using a combination of a user ID and a password. The communication unit 41 transmits the authentication result (success or failure) to the device 20. If the authentication result is successful, the communication unit 41 transmits the usage restriction information stored in the usage restriction information storage unit 49 to the device 20.

[0111] S33: The communication unit 21 of the device 20 receives the authentication result. If the authentication is successful, the communication unit 21 receives the usage restriction information. The display control unit 22 of the device 20 closes the login screen and displays a screen (home screen) on which the device 20 can be used. The usage restriction information is reflected on the home screen, and only functions that can be used by the guest user are displayed, and functions that cannot be selected are displayed with reduced brightness. The usage restriction information is also reflected on lower-level screens that branch off from the home screen.

[0112] S34: If the authentication is successful, the display control unit 22 of the device 20 displays an error dialog.

[0113] In this way, even if a guest user does not have account information, the guest user can log in to the device 20 and use the device 20.

[0114] <<Login screen>> 15 is an example of a login screen 220 displayed by the device 20. Each item on the login screen 220 will be described.

[0115] The user ID field 221 and password field 222 are fields where a general user enters a user ID and password, respectively.

[0116] The login button 223 is a button for a general user to request authentication from the authentication server 40 using the user ID in the user ID field 221 and the password in the password field 222 .

[0117] The guest login button 224 is a button that a guest user presses when logging in, and is displayed only on devices 20 that have the guest login function enabled. Guest users do not need to enter a user ID and password. The device 20 may highlight the guest login button 224 with an arrow or the like and display a message such as "Guests, please press this button to log in."

[0118] <Major Effects> As described above, the information processing system 100 of this embodiment allows a guest user to use the device 20 even if the guest user does not know (enter) the user account information. When a guest user logs in, the information processing device 10 can restrict the functions of the device 20 using the usage restriction information. The device 20 can display a guest login button only when guest user login is permitted.

[0119] <Other application examples> The best mode for carrying out the present invention has been described above using examples, but the present invention is not limited to these examples in any way, and various modifications and substitutions can be made within the scope that does not deviate from the gist of the present invention.

[0120] For example, if a setting is made for each device 20 to permit login by guest users, and if a guest user holds a guest IC card over the device 20, the guest login button 224 may be displayed. Alternatively, even if a setting is made for each device 20 not permitting login by guest users, the guest login button 224 may be displayed when a guest user holds a guest IC card over the device 20.

[0121] The login button may also be a hard key. In this case, the device 20 disables the hard key depending on whether or not the device 20 is set to allow guest users to log in. If the hard key is enabled, the device 20 may display a message such as "Press the triangle button to log in."

[0122] The login screen displayed by the device 20 may be displayed by the device 20 based on a web page generated by the information processing device 10. In this case, the information processing device 10 transmits screen information of a login screen with or without a login button for guest users to the device 20, depending on a setting for whether or not to permit guest users to log in. Similarly, for the usage restriction setting, the information processing device 10 generates a screen on which guest users can select functions that they can use, based on the device usage restriction setting, and transmits the screen information to the device 20.

[0123] 6 is an example, and multiple blocks may be realized as a single block, one block may be divided into multiple blocks, and / or some functions may be moved to another block.Furthermore, the functions of multiple blocks having similar functions may be processed in parallel or in time-sharing by a single piece of hardware or software.

[0124] Furthermore, the devices described in the examples are merely illustrative of one of multiple computing environments for implementing the embodiments disclosed herein. In one embodiment, information processing apparatus 10 includes multiple computing devices, such as a server cluster, configured to communicate with each other via any type of communication link, including a network, shared memory, etc., and to perform the processes disclosed herein.

[0125] Furthermore, the information processing device 10 can be configured to share the processing steps disclosed in this embodiment, such as those shown in Figures 11 and 14, in various combinations. For example, a process executed by a specific unit can be executed by multiple information processing devices included in the information processing device 10. Furthermore, the information processing device 10 may be integrated into one server device or may be divided into multiple devices.

[0126] Furthermore, each function of the above-described embodiments can be realized by one or more processing circuits. Here, the term "processing circuit" in this specification includes a processor programmed to perform each function by software, such as a processor implemented by an electronic circuit, as well as devices such as an ASIC (Application Specific Integrated Circuit), a DSP (Digital Signal Processor), an FPGA (Field Programmable Gate Array), and conventional circuit modules designed to perform each of the above-described functions. [Explanation of symbols]

[0127] 10. Information processing equipment 20 equipment 40 Authentication Server 100 Information Processing Systems [Prior art documents] [Patent documents]

[0128] [Patent Document 1] Patent Publication No. 2021-056982

Claims

1. An information processing system including an information processing device and a device that communicates with the information processing device via a network, The information processing device includes: a setting reception unit that transmits screen information of a guest login setting screen that receives settings related to temporary users to a terminal device that can communicate with the information processing device via a network, receives settings of account information from the terminal device, and stores the received account information in the information processing device; a communication unit that requests an authentication server to store the account information; The device comprises: an authentication control unit that requests the account information from the information processing device when a predetermined operation is received; the communication unit transmits the account information to the device; The information processing system is characterized in that the authentication control unit requests authentication from the authentication server by specifying the account information received from the information processing device, and obtains an authentication result.

2. In the information processing device, whether or not to permit login of a temporary user is registered in association with the identification information of the device, the communication unit transmits to the device whether or not to permit login of the temporary user; 2. The information processing system according to claim 1, wherein the device displays an operation component for accepting the predetermined operation when a notification that the temporary user is permitted to log in is received.

3. The information processing system according to claim 1 or 2, characterized in that when the device receives an authentication result from the authentication server indicating that authentication was successful, the device restricts the functions of the device in accordance with the temporary user's usage restriction information received from the authentication server.

4. The information processing system further includes the terminal device, The terminal device displays a temporary user usage restriction setting screen, the terminal device accepts settings of the usage restriction information of the device inputted to the usage restriction setting screen; 2. The information processing system according to claim 1, wherein the terminal device requests the authentication server to store the use restriction information of the temporary user by specifying the account information.

5. the setting reception unit receives a setting for each of the devices, which is input to the guest login setting screen from the terminal device, as to whether or not to permit login by the temporary user; 5. The information processing system according to claim 1, wherein the setting acceptance unit stores in the information processing device whether or not to permit login of the temporary user in association with the device number of the device.

6. An authentication method performed by an information processing system including an information processing device and a device that communicates with the information processing device via a network, a step in which the information processing device transmits screen information of a guest login setting screen for accepting settings related to a temporary user to a terminal device that can communicate with the information processing device via a network, accepts settings of account information from the terminal device, and stores the accepted account information in the information processing device; requesting an authentication server to store the account information; a step of requesting the account information from the information processing device when the device receives a predetermined operation; a step of the information processing device transmitting the account information to the device; the device requests authentication from the authentication server by specifying the account information received from the information processing device, and acquires an authentication result; 1. An authentication method comprising:

7. A setting reception unit that transmits screen information of a guest login setting screen that accepts settings related to temporary users to a terminal device that can communicate with the information processing device via a network, accepts settings of account information from the terminal device, and stores the accepted account information in the information processing device; a communication unit that requests an authentication server to store the account information; and a device that communicates with the information processing device via a network, When a predetermined operation is received, the authentication control unit functions as an authentication control unit that requests the account information from the information processing device; the authentication control unit requests authentication from the authentication server by specifying the account information received from the information processing device, and acquires an authentication result; program.

8. A setting reception unit that transmits screen information of a guest login setting screen that accepts settings related to temporary users to a terminal device that can communicate with the information processing device via a network, accepts settings of account information from the terminal device, and stores the accepted account information in the information processing device; a communication unit that requests an authentication server to store the account information, and the communication unit communicates with the information processing device via a network, an authentication control unit that requests the account information from the information processing device when a predetermined operation is received; the authentication control unit requests authentication from the authentication server by specifying the account information received from the information processing device, and acquires an authentication result; The device characterized by:

Citation Information

Patent Citations

  • Image processing system, image processing apparatus and its control method, and computer program

    JP2008206114A

  • Image processor, function use control method, function use control program and recording medium with the same program recorded

    JP2012155512A

  • Image formation device, control method thereof, and program

    JP2014144619A

  • Information processing apparatus and program

    JP2018028878A

  • Authentication system, shared terminal, and authentication method

    JP2021056982A