Information processing apparatus and device management method

The information processing apparatus and method manage printing devices to prevent user information leakage by acquiring individual and initialization information, determining device resets, and prohibiting access, ensuring data privacy during user transfers.

JP7792073B2Active Publication Date: 2025-12-25BROTHER KOGYO KK
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2021161718
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-09-30
Publication Date
2025-12-25
Estimated Expiration
2041-09-30

AI Technical Summary

Technical Problem

Existing technologies fail to prevent user information leakage after the usage contract period expires in image forming devices, even when connected to a server and managed using user information.

Method used

An information processing apparatus and method that manages printing devices based on user information, including individual information acquisition, initialization identification, and access prohibition processes to prevent user information leakage during user transfers.

Benefits of technology

Prevents leakage of user information by ensuring new users cannot access previous user data after a device transfer, maintaining data privacy and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007792073000001
    Figure 0007792073000001
  • Figure 0007792073000002
    Figure 0007792073000002
  • Figure 0007792073000003
    Figure 0007792073000003
Patent Text Reader

Abstract

To provide an information processor and a device management method which prevent leakage of user information after use end.SOLUTION: A processor of a data processing server acquires a product ID of a composite machine X, acquires a request instruction of a new server device ID capable of identifying whether or not a factory reset of a composite machine 200 is performed, determines whether or not a factory reset by users A and B accompanying user transfer to a user C from the users A and B for the composite machine X corresponding to the product ID has been performed on the basis of the request instruction of the product ID and the new server device ID, and executes processing of prohibiting access to user information of the users A and B by the user C when determining that the factory reset of the composite machine X has been performed.SELECTED DRAWING: Figure 9
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an information processing apparatus capable of communicating with a printing apparatus via a network, and a device management method using the same. [Background technology]

[0002] Conventionally, as described in Patent Document 1, for example, there is known a technique for storing, in the HDD of an image forming apparatus, unique information specific to the image forming apparatus and change information that is changed in response to deletion of registered data. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2012-44486 Summary of the Invention [Problem to be solved by the invention]

[0004] In the technology described in Patent Document 1, when the registered data is deleted from an image forming device whose usage contract period has expired, the serial number and model name, which are the unique information stored in the HDD, are not deleted, but the change information is deleted. However, even if such processing is performed within the image forming device, if the image forming device is connected to a server and managed using user information, for example, there is a problem that the user information may be leaked from the server after the usage contract period has expired.

[0005] An object of the present invention is to provide an information processing apparatus and a device management method that can prevent user information from being leaked after use has ended. [Means for solving the problem]

[0006] In order to achieve the above object, the present invention provides an information processing device having a communication I / F capable of communicating via a network with a printing device that forms an image on a printing medium, and a control unit that manages the printing device based on user information of a corresponding user, wherein the control unit executes an individual information acquisition process that acquires individual information of the printing device, an initialization identification information acquisition process that acquires initialization identification information that can identify whether information initialization of the printing device has been performed, an initialization determination process that determines whether information initialization has been performed by the first user in connection with a user transfer from a first user to a second user for a specific printing device corresponding to the individual information, based on the individual information acquired in the individual information acquisition process and the initialization identification information acquired in the initialization identification information acquisition process, and an access prohibition process that prohibits access by the second user to the user information of the first user when it is determined by the initialization determination process that information initialization of the specific printing device has been performed.

[0007] In the information processing device of the present invention, a printing device is managed based on at least the user information of the user of the printing device. In the case of a user transfer, such as a transfer from a first user to a second user, leakage of the first user's user information is prevented.

[0008] That is, the control unit acquires the individual information of the printing device in the individual information acquisition process, and acquires the initialization identification information in the initialization identification information acquisition process. The initialization identification information is information that can identify whether or not the information of the printing device has been initialized. The control unit executes an initialization determination process based on the acquired individual information and initialization identification information. The initialization determination process determines whether or not the information of the specific printing device corresponding to the individual information has been initialized by the first user in connection with user transfer. If it is determined that the information of the specific printing device has been initialized, the control unit executes an access prohibition process, thereby prohibiting the second user from accessing the user information of the first user.

[0009] According to the present invention, even when the former user's use ends and the user is transferred to a new user, the new user cannot access the former user's user information, so that leakage of the former user's user information to the new user can be prevented. [Effects of the Invention]

[0010] According to the present invention, it is possible to prevent the leakage of user information after use has ended. [Brief explanation of the drawings]

[0011] [Figure 1] 1 is a functional block diagram illustrating an overall schematic configuration of a printing system according to an embodiment of the present invention. [Figure 2] FIG. 10 is a diagram illustrating a software processing division configuration between a data processing server and a multifunction peripheral in a comparative example. [Figure 3] 10 is a diagram illustrating a comparative example of a software processing sharing configuration between a data processing server and a multifunction peripheral according to an embodiment. FIG. [Figure 4] FIG. 10 is a diagram illustrating an example of a specific association configuration between a logical device and a physical device. [Figure 5] FIG. 10 is a diagram illustrating a state in which the actual multifunction peripheral is normally set up and the printing service is available. [Figure 6] FIG. 10 is a diagram showing changes in each data and association configuration when the actual multifunction peripheral is factory reset. [Figure 7] 10A and 10B are diagrams showing changes in the data and association configuration when the transferred actual multifunction device is re-set up. [Figure 8] FIG. 10 is a diagram illustrating a state in which a physical device is transferred and associated with a transferred actual multifunction peripheral. [Figure 9] FIG. 10 is a diagram showing a state in which only non-personal information is extracted from the original service-related information table, transferred to a new logical device, and associated therewith. [Figure 10] FIG. 10 is a diagram showing the data and association configuration when re-setup of the transferred actual multifunction peripheral is completed. DETAILED DESCRIPTION OF THE INVENTION

[0012] A printing system according to an embodiment of the present invention is shown in Fig. 1. This embodiment is an embodiment of a printing system 1 that provides a prepaid printing service in which a customer user pays a fee to use the printing function of a multifunction peripheral 200.

[0013] <1: Printing system overview> 1, the printing system 1 includes a data processing server 100, a multifunction device 200, an information terminal 300, and a transaction server 400. The data processing server 100, the multifunction device 200, the information terminal 300, and the transaction server 400 are connected to a network NT and can communicate with each other.

[0014] <1-1: Data processing server> The data processing server 100 is a server installed and managed by, for example, the manufacturer of the multifunction peripheral 200, and includes a processor 110, a storage device 115, and an interface 190. The processor 110, the storage device 115, and the interface 190 are connected to one another via a bus 105. The data processing server 100 is an example of an information processing device.

[0015] The storage device 115 includes a volatile storage device 120 and a non-volatile storage device 130 . The volatile storage device 120 is, for example, a DRAM, and stores appropriate data for managing the multifunction peripheral 200 (described later). The non-volatile storage device 130 is, for example, a hard disk drive or a solid state drive, and has a program storage area 131 and a data management table 132. The contents of each will be described in detail later.

[0016] The processor 110 is a device that performs data processing, such as a CPU. The processor 110 executes programs stored in the program storage area 131 to perform various processes shown in Figs. 4 to 10, which will be described later, including data communication with the information terminal 300, the multifunction peripheral 200, and the transaction server 400 connected to the network NT. The programs 131, etc. in the storage device 115 and the processor 110 that uses them are an example of a control unit.

[0017] The interface 190 is a wired LAN interface or a wireless interface for communicating with other devices, and is connected to the network NT via a wide area communication interface (not shown). The interface 190 is an example of a communication I / F.

[0018] <1-2: Trading Server> The transaction server 400 is installed, for example, in a company that provides various online services for performing online settlements, and has a processor, a storage device, and an interface for connecting to the network NT (not shown).

[0019] <1-3:Multifunction device> The multifunction peripheral 200 is owned, for example, by a business that provides the printing service. The multifunction peripheral 200 is an example of a printing device. The multifunction peripheral 200 has a scanner unit 280, a printing unit 290, a processor 210, a storage device 220, a display unit 240, an operation unit 250 that can be operated by a user, and a communication interface 270. The scanner unit 280, the printing unit 290, the processor 210, the storage device 220, the display unit 240, the operation unit 250, and the communication interface 270 are connected to one another via a bus 205.

[0020] The storage device 220 includes a volatile storage device 221, a nonvolatile storage device 223, and a powered volatile storage device 225. The volatile storage device 221 is, for example, a DRAM and includes a data storage area 222 capable of storing image data. The nonvolatile storage device 233 is, for example, a flash memory. The nonvolatile storage device 230 includes a program storage area 224. Of the various programs stored in the program storage area 224, management processing programs related to data management and sequence flow execution, such as those shown in Figures 4 to 10, are stored in advance as firmware, for example. The powered volatile storage device 225 is, for example, an NVRAM equipped with its own battery power source and capable of retaining its stored contents even when the main power of the multifunction peripheral 200 is turned off, and stores setting data, described below, in a partially erasable or rewritable manner. The powered volatile storage device 225 is an example of a storage unit.

[0021] The processor 210 is a device that performs data processing, such as a CPU. The processor 210 executes the management processing program stored in the program storage area 224 and various print control programs for the multifunction device 200. This allows the processor 210 to cause the printing unit 290 to print an image based on image data transmitted from the information terminal 300.

[0022] The display unit 240 is, for example, a liquid crystal display. The operation unit 250 is a device that accepts operations by the user. The user can input various instructions to the multifunction device 200 by operating the operation unit 250. The communication interface 270 is a wired or wireless network interface for communicating with other devices, and is connected to the network NT via a wide area communication interface (not shown).

[0023] The scanner unit 280 optically reads an original document, which is an object to be read, using a photoelectric conversion element such as a CCD or CMOS, and generates image data representing the read image.

[0024] The printing unit 290 uses a transport mechanism (not shown) to pick up and transport paper from a paper feed tray, and prints an image on the transported paper using a predetermined method. The following explanation uses an example of inkjet printing. Note that paper is an example of a print medium.

[0025] <1-4: Information terminal> In this example, the information terminal 300 is an information terminal such as a desktop PC, tablet PC, or smartphone owned by a user, and is connected to the network NT via wireless communication, for example. The information terminal 300 has a processor, a storage device, and an interface for connecting to the network NT (not shown). In this example, the processor of the information terminal 300 uses an OS (Operating System) equipped with so-called general-purpose printing functions such as Mopria and AirPrint. The information terminal 300 is also pre-installed with an application program that runs and runs on this OS and is used to receive the above-mentioned printing service. Note that instead of the information terminal 300, other information terminals such as a personal computer or tablet computer may be used.

[0026] <2: Logical devices and physical devices> As described above, the printing system 1 of this embodiment provides a prepaid printing service in which a user pays a fee to use the printing function of the multifunction peripheral 200. Specifically, a customer user uses a printing service under a usage contract using a multifunction peripheral 200 owned by a printing service provider or a multifunction peripheral 200 purchased by the user. When using the service, the user purchases in advance via the information terminal 300 the right to print a specified number of pages for the multifunction peripheral 200, i.e., a pay-as-you-go system in which only the specified number of pages corresponding to the specific printing service plan ordered can be printed. In this case, the data processing server 100 directly accepts a printing service order from the information terminal 300, and the transaction server 400 indirectly performs online payment for the order. Once payment is complete, the printing service is applied to the multifunction peripheral 200.

[0027] To perform the above-described print service cooperative processing, the data processing server 100 and the multifunction peripheral 200 may each have a software processing sharing configuration similar to the comparative example shown in FIG. 2. In the illustrated example, the data processing server 100 includes a program corresponding to the multifunction peripheral management processing unit 11, and the multifunction peripheral 200 includes programs corresponding to the service management processing unit 21, device management processing unit 22, and device control processing unit 23, respectively. The multifunction peripheral management processing unit 11 of the data processing server 100 comprehensively manages information about the multiple multifunction peripherals 200 under the control of the data processing server 100. The service management processing unit 21 of the multifunction peripheral 200 processes print service orders from contracted users of the multifunction peripheral 200 and manages related information. The device management processing unit 22 manages the mechanical status of the multifunction peripheral 200, such as consumables and abnormalities. The device control processing unit 23 performs processing related to basic device control of the multifunction peripheral 200, such as printing operations, operations, and displays. The above-described prepaid printing service can be realized even with this configuration in which software processing is shared between the data processing server 100 and the multifunction device 200. However, this sharing configuration limits the degree of freedom in various settings, making it difficult to flexibly accommodate tasks such as re-setup when the multifunction device 200 is transferred between users, as will be described later.

[0028] 3, the present embodiment has a sharing configuration in which the service management processing unit 21 and the device management processing unit 22 are configured to process the respective individual multifunction peripherals 200 on the data processing server 100 side. In this case, the service management processing unit 21 performs the service management processing using a logical device LD as a virtual machine that is not linked to a specific multifunction peripheral 200, and the device management processing unit 22 performs the device management processing using a physical device PD that is linked to a specific multifunction peripheral 200.

[0029] <3: About the association configuration between logical devices and physical devices> FIG. 4 shows an example of a specific association configuration between these logical devices LD and physical devices PD. First, the logical device LD itself is individually identified by an ID ("ID:****" in the example shown in the figure) that is appropriately uniquely assigned for each service contract. The account of a contracted user registered in the data processing server 100 is associated with this logical device LD. Note that the association of users with this logical device LD can be switchable in various combinations, such as linking multiple users to one logical device LD, or conversely, linking multiple logical devices (i.e., multiple multifunction peripherals 200) to one user. Similarly, the physical device PD itself is individually identified by an ID ("ID:△△△△" in the example shown in the figure) that is appropriately uniquely assigned. Each individual actual multifunction peripheral 200 is always associated with this physical device PD in a one-to-one fixed manner based on a combination of a product ID and a server device ID, which will be described later, and its mechanical status can be referenced in real time (hereinafter, this referable state is referred to as "affiliation"). The physical device PD is switchably associated with the logical device LD in a specified combination.

[0030] The logical device LD and physical device PD are used to manage data corresponding to their respective processing contents. The logical device LD manages various pieces of information related to the associated user's printing service as a data table. Specifically, the managed information includes order information, point information, coupon information, print count history information, consumables ordering information, and tutorial charge information. In this example, the user selects and orders printing rights for the multifunction peripheral 200 from among several charge service plans, such as 100 sheets = 100 yen or 300 sheets = 250 yen. A number of these service plans are prepared in advance on the data processing server 100 (not shown). Service points corresponding to a certain percentage of the order charge are awarded. Coupons that qualify for free orders worth a certain amount are also issued during promotional events, etc. In the above printing service, information related to the order's purchase history and charge history is managed as order information associated with separately generated receipt data (not shown), service point information is managed as point information, and coupon information is managed as coupon information. The print count history information is information that manages the number of prints actually made by the service out of the number of sheets that the user charged to the multifunction device 200 in past orders. The consumables order information is information that manages the content of orders that the user has made in the past for consumables such as ink cartridges for the multifunction device 200.

[0031] In addition to the billing orders and coupons described above, the printing service in this example also offers a tutorial charge service plan as one way to charge the printable number of pages for the multifunction peripheral 200. This tutorial charge is a one-time charge authorization that can be applied free of charge or at a significant discount for business purposes, such as helping first-time users of the multifunction peripheral 200 learn the charging operation or ensuring initial use of the multifunction peripheral 200. In this embodiment, the application of the service points and coupons described above can be freely set as appropriate for the business model, such as per user, per logical device LD, or per physical device PD (per multifunction peripheral 200). However, for the above-mentioned purpose, this tutorial charge is set to be applicable only once per initial purchase of a newly sold multifunction peripheral 200. The tutorial charge information indicates whether the tutorial charge has already been applied. As described below, even if a single multifunction peripheral 200 is repeatedly transferred and users change, this information is inherited and commonly referenced by each associated logical device LD each time it is set up.

[0032] Furthermore, various information related to the mechanical status of each individual multifunction peripheral 200 belonging to the physical device PD is managed as a device individual information table. Specific examples of the managed information include remaining charge number information, consumable information, abnormality information, product ID, and service device ID. The remaining charge number information is information that manages the remaining number of printable pages out of the number of pages that the user has charged the corresponding multifunction peripheral 200. The consumable information is information that manages the current remaining amount and status of consumables such as ink cartridges in the corresponding multifunction peripheral 200. The abnormality information is information that manages any unauthorized operation performed on the corresponding multifunction peripheral 200, or any abnormality or malfunction that has occurred. The product ID is identification information uniquely assigned to each individual multifunction peripheral 200 belonging to the corresponding physical device PD, as will be described later. The service device ID is identification information uniquely assigned to each individual multifunction peripheral 200 when registering the corresponding multifunction peripheral 200 so that it can be managed on the data processing server 100 side, as will be described later. As a result, the identification ID of the physical device PD itself can be uniquely associated with the combination of the product ID and the service device ID and can be specified.

[0033] In the multifunction peripheral 200, setting data is stored in the powered volatile storage device 225. In the multifunction peripheral 200 of this embodiment, a user can perform a factory reset via the operation unit 250 to return the multifunction peripheral 200 to its factory default state. The setting data storage area in the powered volatile storage device 225 is divided into a reset erase area 225a, where the stored contents are erased by the factory reset, and a reset non-erasure area 225b, where the stored contents are not erased even after the factory reset. The reset erase area 225a stores personal setting data, such as a phone number and email address, separately set by the user when using the multifunction peripheral 200, and server registration information, which indicates whether the multifunction peripheral 200 is registered for use so that it can be managed by the data processing server 100.

[0034] Furthermore, the reset non-erasure area 225b stores a product ID and a server device ID. The product ID is, for example, information that combines information about the model name of the multifunction device 200 and information about the serial number assigned to each multifunction device 200 when it is manufactured in a factory, and is identification information that can identify one individual multifunction device 200 among the many multifunction devices 200 that are distributed and used on the market. This product ID is treated as immutable stored information that will never be erased or changed under any circumstances.

[0035] The server device ID corresponds to a registration ID that is generated and assigned by the data processing server 100 to each application for user registration when the multifunction peripheral 200 is registered with the data processing server 100 so that the multifunction peripheral 200 can use the printing service. In other words, after a factory-shipped multifunction peripheral 200 is purchased and used as a new product, it may be transferred and used repeatedly between different users, for example, through a secondhand machine market. Each time the multifunction peripheral 200 is transferred and re-setuped to use the printing service, a new server device ID is generated and assigned by the data processing server 100 each time a connection to the data processing server 100 via the network NT is established and a registration application is made. This makes it possible to distinguish the same multifunction peripheral 200 for each registration and to set and identify a physical device PD that is uniquely associated with the combination of the product ID and service device ID.

[0036] In this embodiment, among the various data described above, the order information, user-issued point information, and print count history information (see underlined information in the figure) are protected from leakage between users with different user registrations. That is, even if the multifunction device 200 is repeatedly transferred, these data are stored as personal information associated with the user corresponding to each user registration, while being prohibited from access by users with other user registrations. Furthermore, when the multifunction device 200 is transferred, the remaining charge number information, consumable information, error information, and product ID data are inherited and made available for reference as the most recent data representing the mechanical condition of the multifunction device 200 at the time of transfer. The registered personal data stored in the powered volatile storage device 225 of the multifunction device 200 is also personal information that is protected from leakage to other users, and this registered personal data is erased by the user who registered it during a factory reset before the transfer.

[0037] In the above, order information is an example of paid printing authority information, point information is an example of free printing authority information, coupon information and tutorial charge information are examples of device printing authority information, print count history information is an example of printed volume information, consumables order information is an example of consumables order information, and user account, order information, point information, and print count history information are examples of user information. Also, product ID is an example of individual information, factory reset is an example of information initialization, the contents of the service-related information table are an example of service information, reset-erase area 225a is an example of a first storage area, and reset-non-erase area 225b is an example of a second storage area.

[0038] <4: Sequence for normal use and re-setup after reset> Next, the processing sequences of various data and devices during normal use in the printing system 1 of this embodiment and during re-setup after the transfer of the multifunction peripheral 200 will be described with reference to Figures 5 to 10. Note that in each figure, various data and the like are shown as necessary, and are otherwise omitted as appropriate.

[0039] First, FIG. 5 shows a state in which the multifunction device 200 (referred to in the figure as "multifunction device X," meaning a single individual device) has been set up and registered for use in the data processing server 100 in the normal manner, thereby enabling the use of the print service. In this illustrated example, the multifunction device X is configured to belong to a system of physical device PD1 and logical device LD1 within the data processing server 100. In the illustrated example, two users A and B's accounts are linked to one logical device LD1, allowing both users A and B to use the print service in common. In this example, the tutorial charge, which is a first-time purchase bonus for the multifunction device X, has already been applied, and the tutorial charge information flag in the service-related information table 1 referenced by the logical device LD1 is recorded as "applied" (the check box in the figure is filled in).

[0040] Furthermore, the device individual information table 1 referenced by the physical device PD1 records the product ID of the actual multifunction device X and the server device ID-1 issued at the time of user registration (not shown in FIG. 5). In the actual multifunction device X, the reset erase area 225a of the powered volatile storage device 225 records set personal data such as telephone numbers and email addresses set by users A and B, and also records the server registration information flag as registered (the check box in the figure is filled in). Furthermore, the reset non-erasure area 225b records the product ID of the actual multifunction device X and the server device ID-1 issued by the data processing server 100 at the time of user registration.

[0041] In this state, the data processing server 100 has a number of selectable charging plans (not shown) prepared in advance, and order processing is initiated when, for example, user A selects a specific charging plan via the information terminal 300 and instructs its purchase and use. At this time, after user A completes payment for the charging plan via a separate transaction server 400, the order processing updates the remaining charge number information in the physical device PD by increasing it by the charge number of the charging plan. The physical device PD also transmits the charge number to the associated actual multifunction device X. This allows user A to order the charging plan of his or her choice and charge the printable number of sheets in the actual multifunction device X by the corresponding charge number.

[0042] The management of the generation of service points and the issuance of coupons based on the accumulated points are performed by appropriate processing between the data processing server 100 and the transaction server 400. Coupons that are free order rights are registered as selectable types of charge plans in the data processing server 100. When a user uses the coupon, the user immediately instructs the logical device LD to charge the number of prints corresponding to the coupon without waiting for payment. After that, a used flag is attached to the coupon information (the above is not shown).

[0043] For example, when users A and B transfer the actual multifunction device X, they perform a factory reset to erase the personal settings data and other information stored therein. As a result, as shown in FIG. 6, the personal settings data and the server registration information flag are erased in the reset erase area 225a of the powered volatile storage device 225. Meanwhile, the product ID and server device ID-1 information in the reset non-erase area 225b are not erased and are retained even if the main power of the actual multifunction device X is turned off for an extended period of time. Furthermore, this factory reset process can be performed independently by the actual multifunction device X itself, and the data processing server 100 is not involved in any way. Therefore, immediately after the reset, the data processing server 100 cannot determine that a reset has been performed on the actual multifunction device X, and continues to retain the corresponding physical device PD1 and logical device LD1, as well as the data they reference.

[0044] Thereafter, when the actual multifunction device X is reset at the transferee, the process shown in Fig. 7 is carried out. First, when the power is turned back on to the actual multifunction device X in a reset state, an initialization routine is used to check the recording state of the server registration information flag, and based on the erased state, it is determined that the actual multifunction device X itself has been factory reset. When the actual multifunction device X that has been determined to be in a reset state is connected to the data processing server 100 via the network NT, it transmits the product ID and information about the previous server device ID-1 that are recorded in the reset non-erasure area 225b at that time, and requests the data processing server 100 to issue a new server device ID.

[0045] Upon receiving the product ID, server device ID-1, and the request to issue a new server device ID, the data processing server 100 determines that the actual multifunction device X has been reset, and processes the request as if a new registration for use of the print service has been applied for. Specifically, the data processing server 100 generates a new server device ID-2 uniquely in response to the registration, and returns and assigns it to the actual multifunction device X. Also, in response to the registration, the data processing server 100 sets up a new logical device LD2 to which the newly generated unique identification ID has been assigned.

[0046] The actual multifunction device X then updates the reset non-erasure area 225b by overwriting the received new server device ID-2, and sets a flag for server registration information to record the registered state. At this point, user C of the actual multifunction device X can access the data processing server 100 via the information terminal 300 and associate his or her account with the new logical device LD2 by performing authentication such as verifying the product ID or server device ID-2.

[0047] 8, the data processing server 100 identifies the physical device PD1 associated with the previous registration of the actual multifunction device X based on the received product ID and server device ID-1. The data contents of the device individual information table 1 referenced by this physical device PD1, excluding the server device ID, most closely correspond to the mechanical state of the actual multifunction device X at that time. Therefore, the entire data contents of the device individual information table 1, along with the physical device PD1 itself, are extracted and transferred to belong to a new logical device LD2, and the server device ID reflects the new server device ID-2. Furthermore, the actual multifunction device X is set to belong to the physical device PD1 anew. As a result, the actual multifunction device X is completely separated from the system of the previous logical device LD1, and access from the original users A and B is blocked.

[0048] As shown in FIG. 9, the device-issued coupon information and consumables order information are extracted from the data contents of service-related information table 1 referenced by the previous logical device LD1 and stored as new service-related information table 2, which is referenced only by the user of the new logical device LD2. The other data contents of service-related information table 1, such as order information, user-issued points information, and print count history information, remain stored in service-related information table 1 and are referenced only by the user of logical device LD1. Only the tutorial charge information is stored in both the previous service-related information table 1 and the new service-related information table 2. As a result of executing the above sequence, as shown in FIG. 10, the flow of information between users A and B, who previously used the same actual multifunction device X, and user C, who will now use it, is completely separated, preventing the flow (leakage) of protected information held by each.

[0049] The distinction between transfer and retention of the above-mentioned service-related information by extracting each piece of data is determined by the business model of the printing service. Specifically, the order information associated with receipt data, the user-issued points information issued in accordance with the user's billing history, and the print count history information associated with the user's charge history are all considered to be user personal information for the corresponding user registration and should not be disclosed to other users. However, the transfer targets, such as device-issued coupon information issued exclusively to individual devices of multifunction device 200 and consumables order information with a limited number of orders per device, are information referenced in association with individual devices of multifunction device X and therefore must always be transferred in accordance with the relevant multifunction device X. Furthermore, tutorial charge information must be stored in common across all corresponding user registrations, since it can only be applied once to the relevant multifunction device X.

[0050] In contrast, in this embodiment, user personal protection information is stored in a referable manner in the corresponding logical device LD for each user registration, preventing leakage, and when a previous user registers a new multifunction peripheral 200 again, the previous service-related information data can continue to be applied. Furthermore, information such as services associated with one individual multifunction peripheral 200 is always transferred so that it can be referenced only by the physical device PD corresponding to that individual, preventing multiple users from using the same service for each user registration. Furthermore, for the tutorial charge service, even if the same individual multifunction peripheral 200 is repeatedly registered for use, the one-time application is maintained.

[0051] In the above, the actual multifunction device X is an example of a specific printing device, users A and B are examples of a first user, user C is an example of a second user, logical device LD1 is an example of a first logical device, physical device PD1 is an example of a specific physical device, logical device LD2 is an example of a second logical device, the process of receiving a product ID on the data processing server 100 side is an example of an individual information acquisition process and an individual information acquisition step, a request for a new server device ID sent from the actual multifunction device X is an example of initialization identification information, the process of receiving a request for a new server device ID on the data processing server 100 side is an example of an initialization identification information acquisition process and an initialization identification information acquisition step, and the process of determining whether the actual multifunction device X has been reset on the data processing server 100 side is an example of an initialization determination process and an initialization determination step. This is an example of an access prohibition process and an access prohibition step, and the process of linking a user's account with a logical device LD on the data processing server 100 side is an example of a user registration process. The process of extracting physical device PD1 from the logical device LD1 system and transferring it to a new logical device LD2 is an example of an association update process. The process of making personal protection information in the service-related information table 1 of users A and B invisible to user C due to differences in the affiliation of such logical devices LD is an example of a correction process. The process of associating information in the service-related information table 1 other than the personal protection information so that it can be referenced with the new logical device LD2 is an example of a service registration process.

[0052] <5: Effects of the embodiment> As described above, in the data processing server 100 provided in the printing system 1 of this embodiment, the multifunction device 200 is managed based on at least the user information of the user of the multifunction device 200. When the multifunction device 200 is transferred to another user, such as transferred from users A and B to user C, leakage of the user information of users A and B is prevented.

[0053] That is, the processor 110 acquires the product ID of the multifunction device 200 and a request instruction for a new server device ID. The request instruction for a new server device ID is information that can identify whether or not a factory reset has been performed on the multifunction device 200. The processor 110 determines whether or not a factory reset has been performed on the actual multifunction device X based on the acquired product ID and request instruction for a new server device ID. In this way, it is determined whether or not a factory reset has been performed on the actual multifunction device X corresponding to the above product ID by users A and B in connection with a user transfer. If it is determined that a factory reset has been performed on the actual multifunction device X, the processor 110 prohibits user C from accessing the user information of users A and B.

[0054] According to this embodiment, even if former users A and B end their use and the user is transferred to new user C, new user C cannot access the user information of former users A and B, thereby preventing the user information of former users A and B from being leaked to new user C.

[0055] Furthermore, particularly in this embodiment, the processor 110 handles the multifunction peripheral 200 by conceptually dividing it into a physical device PD and a logical device LD associated with the physical device PD. The physical device PD is a concept associated with the product ID of the multifunction peripheral 200. The logical device LD is a concept associated with a service-related information table related to the provision of services related to the multifunction peripheral 200. At least one user account is associated with the logical device LD associated with the service-related information table by the processor 110.

[0056] For example, when users A and B finish using actual multifunction device X and the user is transferred to new user C, the physical device PD1 of actual multifunction device X is taken over. In this embodiment, the processor 110 acquires the product ID at the time of the transfer, thereby acquiring the product ID of actual multifunction device X. In actual multifunction device X from which the product ID was acquired, the product ID was associated with the physical device PD1 of the specific actual multifunction device X.

[0057] If the processor 110 determines based on the acquired product ID that a factory reset has been performed on the actual multifunction device X, the processor 110 updates the association of the physical device PD1. That is, the association between the physical device PD1 related to the actual multifunction device X and the logical device LD1 related to users A and B is discarded, and instead an association between the physical device PD1 and the logical device LD2 related to user C is established. The logical device LD associated with the physical device PD1 changes from the logical device LD1 to the logical device LD2.

[0058] In this embodiment, the service-related information table 1 associated with the logical device LD1 is not associated with the new logical device LD2 as is, but a process of correcting the service-related information table 1 is performed. In this process, appropriate invisibility such as deletion is performed on the contents of the service-related information table 1 associated with the logical device LD1 that are related to at least the user information of users A and B. The service-related information table 1 corrected by this correction process is registered in association with the new logical device LD2.

[0059] According to the data processing server 100 of this embodiment, the multifunction peripheral 200 is conceptually divided into a logical device LD1 associated with the service-related information table 1 and a physical device PD1 associated with the product ID. When a user is transferred from users A and B to user C, the physical device PD1 of the multifunction peripheral 200 is associated with a new logical device LD2 instead of the logical device LD1. The service-related information table 1 associated with the logical device LD1 is associated with the new logical device LD2 after the content related to the user information of users A and B is made invisible. According to this embodiment, when a user is transferred from users A and B to user C, the logical device LD2 newly associated with the physical device PD1 is associated with only the service-related information table 1 after the user information related to users A and B has been made invisible. Since user C cannot access the user information of the original users A and B, it is possible to reliably prevent the user information of users A and B from being leaked to user C.

[0060] In particular, in this embodiment, the powered volatile storage device 225 of the multifunction peripheral 200 includes a reset-erased area 225a and a reset-non-erased area 225b, and the product ID is stored in the reset-non-erased area 225b, which is not erased by a factory reset. According to this embodiment, when the processor 110 acquires a product ID, it can reliably acquire the product ID that has not been erased and is stored in the reset-non-erased area 225b.

[0061] Furthermore, particularly in this embodiment, the processor 110 acquires the request instruction for a server device ID that is generated by erasing the server registered information stored in the reset / delete area 225a when receiving a request instruction for a new server device ID from the multifunction peripheral 200. This allows the multifunction peripheral 200 itself to determine that it has been reset based on the erasure of the server registered information, and the processor 110 can confirm that a request instruction for a new server device ID has been sent.

[0062] In particular, in this embodiment, the contents of the service-related information table 1 include at least one of order information and point information. The order information is obtained by users A and B for a fee, and the point information is given to users A and B free of charge, and both include content related to the user information of users A and B. The content related to the user information is made invisible for at least one of the order information and point information associated with the logical device LD1.

[0063] According to this embodiment, when a user transfer occurs from users A and B to user C, only order information or point information in which the user information of users A and B is made invisible can be associated with the logical device LD2 that is newly associated with the physical device PD1. Since user C cannot access the user information of users A and B, leakage of the user information of users A and B can be reliably prevented.

[0064] In particular, in this embodiment, the service-related information table 1 includes at least one of coupon information, tutorial jersey information, print count history information, and consumables order information. The coupon information and tutorial jersey information are information assigned to the actual multifunction device X, the print count history information is information indicating the amount of prints already made by the actual multifunction device X, and the consumables order information is information corresponding to information on ordering consumables provided in the actual multifunction device X, and none of these information includes content related to the user information of users A and B. The processor 110 does not make any of the coupon information, tutorial jersey information, print count history information, or consumables order information invisible, but instead registers them as they are in association with the new logical device LD2. According to this embodiment, the portions of the service-related information table 1 that are not related to user information can be reliably transferred to the new logical device LD2 as they are.

[0065] In this embodiment, each device is configured to operate using a request for a new server device ID as initialization identification information, but this is not necessarily the case. For example, instead of requesting a new server device ID, information indicating that initialization has been performed may be sent from the actual multifunction device X to the data processing server 100. In this case, a new server device ID is not issued to the actual multifunction device X, but a temporary server device ID is generated within the data processing server 100, and the division shown in FIG. 10 is performed. Furthermore, this information indicating that initialization has been performed may be generated by the actual multifunction device X itself, or may be the specific data after reset, which is the specific data that the actual multifunction device X sent to the processing server 100 was erased by resetting.

[0066] Furthermore, in the above, the sequences shown in Figures 5, 6, 7, 8, 9, 10, etc. do not limit the present invention to the procedures shown in these sequences, and steps may be added or deleted or the order may be changed within the scope that does not deviate from the intent and technical idea of ​​the invention.

[0067] In addition to the above, the methods according to the above embodiments and modifications may be used in appropriate combination.

[0068] Although not specifically illustrated, the present invention can be implemented with various modifications within the scope of the invention. [Explanation of symbols]

[0069] 1 Printing System 100 Data processing server (an example of an information processing device) 110 Processor (an example of a control unit) 200 Multifunction printer (an example of a printing device) 210 processor 225 Powered volatile memory device (an example of a memory unit) 225a Reset erase area (an example of the first storage area) 225b Reset non-erasure area (an example of the second storage area) 300 Information terminal 400 Trade Server LD logical device PD Physical Device NT Network

Claims

1. a communication I / F capable of communicating with a printing device that forms an image on a printing medium via a network; a control unit that manages the printing device based on user information of a corresponding user; An information processing device having: The control unit an individual information acquisition process for acquiring individual information of the printing device; an initialization identification information acquisition process for acquiring initialization identification information that can identify whether information initialization of the printing device has been performed; an initialization determination process that determines whether the information initialization has been performed for the specific printing device corresponding to the individual information, based on the individual information acquired in the individual information acquisition process and the initialization identification information acquired in the initialization identification information acquisition process; an access prohibition process for prohibiting a second user from accessing the user information of the first user when it is determined that the information of the specific printing device has been initialized by the initialization determination process; Run The control unit One of the printing devices can be conceptually divided into a physical device based on the individual information of the printing device and a logical device that is associated with service information related to the provision of services related to the printing device and is associated with the physical device, The control unit further execute a user registration process for registering at least one user in association with the logical device; In the individual information acquisition process, the individual information associated with the physical device related to the printing device is acquired; The access prohibition process includes: an association update process that, when it is determined by the initialization determination process that information initialization of the specific printing device has been performed, discards a previously associated association between a first logical device associated with the first user and a specific physical device associated with the specific printing device, and establishes an association between a second logical device associated with the second user and the specific physical device; a correction process for making invisible at least content related to the user information of the first user among the service information associated with the first logical device; a service registration process for registering the service information corrected by the correction process in association with the second logical device; An information processing device comprising:

2. The printing device a storage unit for storing information; The storage unit a first storage area in which information is erased by the information initialization, and a second storage area in which information is not erased by the information initialization, The control unit The information processing apparatus according to claim 1 , wherein the individual information acquisition process acquires the individual information stored in the second storage area.

3. The control unit The information processing apparatus according to claim 2 , wherein the initialization identification information acquisition process acquires the initialization identification information generated by erasing the information stored in the first storage area.

4. The service information associated with the first logical device The information includes at least one of paid printing authority information acquired by the first user for a fee and free printing authority information granted to the first user free of charge, The control unit 2. The information processing device according to claim 1, wherein the correction process performs a correction to make invisible the content related to the user information of the first user in at least one of the paid printing authority information and the free printing authority information associated with the first logical device.

5. The service information associated with the first logical device The information includes at least one of information on device printing authority granted to the specific printing device, information on the amount of printing already performed by the specific printing device, and ordering information on consumables provided for the specific printing device, The control unit In the correction process, none of the device printing authority information, the print volume information, and the order information is made visible, 5. The information processing apparatus according to claim 1, wherein the service registration process registers the device printing authority information, the print volume information, and the order information in association with the second logical device.

6. A device management method executed by an information processing device that manages a printing device that forms an image on a printing medium based on user information of a corresponding user, comprising: an individual information acquisition step of acquiring individual information of the printing device; an initialization identification information acquisition step of acquiring initialization identification information that can identify whether or not information initialization of the printing device has been performed; an initialization determination step of determining whether the information initialization has been performed for the specific printing device corresponding to the individual information, based on the individual information acquired in the individual information acquisition step and the initialization identification information acquired in the initialization identification information acquisition step; an access prohibition step of prohibiting a second user from accessing the user information of the first user when it is determined in the initialization determination step that the information of the specific printing device has been initialized; and A single printing device can be conceptually divided into a physical device based on the individual information of the printing device and a logical device associated with service information relating to the provision of services related to the printing device and associated with the physical device, moreover, a user registration step of registering at least one user in association with the logical device, The individual information acquisition step acquires the individual information associated with the physical device related to the printing device, The access prohibition step includes: an association updating step of, when it is determined in the initialization determining step that information initialization of the specific printing device has been performed, discarding a previously associated association between a first logical device associated with the first user and a specific physical device associated with the specific printing device, and establishing an association between a second logical device associated with the second user and the specific physical device; a correction step of making the content of the service information associated with the first logical device, the content relating to at least the user information of the first user, invisible; a service registration step of registering the service information corrected in the correction step in association with the second logical device; A device management method comprising:

Citation Information

Patent Citations

  • Information apparatus, image processing apparatus, information processing apparatus which can communicate with the information apparatus and information processing system including them

    JP2011113241A

  • Image processing apparatus and control system

    JP2012044486A

  • Information processing apparatus, control method therefor, and program

    JP2019129342A

  • Communication system, communication apparatus, communication control method and program

    JP2020140223A