An information processing device, control method, and program having a multi-factor authentication function.

The information processing device enables user-selected authentication methods in image forming devices, enhancing security and convenience by allowing customizable multi-factor authentication options.

JP7797145B2Active Publication Date: 2026-01-13CANON KK
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2021143746
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-09-03
Publication Date
2026-01-13
Estimated Expiration
2041-09-03

AI Technical Summary

Technical Problem

Multi-factor authentication in image forming devices can become cumbersome due to the need for combined use of IC cards and PINs, leading to user inconvenience.

Method used

An information processing device that allows users to select at least one authentication method from IC card, PIN, or pattern authentication, with customizable settings controlled by an administrator.

Benefits of technology

Enhances security and improves user convenience by allowing method selection in multi-factor authentication settings, reducing the burden of multiple authentication steps.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007797145000002
    Figure 0007797145000002
  • Figure 0007797145000003
    Figure 0007797145000003
  • Figure 0007797145000004
    Figure 0007797145000004
Patent Text Reader

Abstract

To provide an information processing device, control method and program, which allow a user to select at least one of multi-factor authentication methods to improve convenience of multi-factor authentication while enhancing security.SOLUTION: An information processing device provided herein is configured to authenticate a user through at least a first authentication process and a second authentication process and allow the authenticated user to use at least one of multiple functions, and comprises control means for providing control to let the user select an authentication method to be used in the first authentication process when authenticating the user through at least the first authentication process.SELECTED DRAWING: Figure 5
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] This proposal relates to an information processing device, a control method, and a program that have a multi-factor authentication function. [Background technology]

[0002] In recent years, cyber attacks have become more sophisticated, and the introduction of multi-factor authentication as a countermeasure is progressing. There are three elements used in multi-factor authentication: "knowledge information," "possession information," and "biometric information." "Knowledge information" is authentication information known only to the individual, such as a PIN number or pattern. "possession information" refers to an IC card that only the individual possesses, or a USB dongle that performs authentication by inserting a security key into a USB port. "Biometric information" refers to information or characteristics unique to the individual's living organism, such as fingerprints, veins, or face.

[0003] By using multi-factor authentication, which combines multiple types of "knowledge information," "possessive information," and "biometric information," it is possible to counter cyber attacks and reduce the risk of unauthorized use of the system.

[0004] When using an image forming device such as a multifunction printer installed in an office, a known method of authenticating a user is to use an employee ID card (IC card). This method is convenient and widely used because user authentication can be completed simply by holding up the IC card. Meanwhile, Patent Document 1 discloses an image forming device that provides a multi-factor authentication method that combines an IC card, which is "possessed information," with biometric authentication and other authentication methods. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Patent Publication No. 2019-155610 Summary of the Invention [Problem to be solved by the invention]

[0006] As mentioned above, image forming devices that employ multi-factor authentication are known. However, when an administrator of an image forming device enables multi-factor authentication, while security is enhanced, there is also the issue that the authentication process can become cumbersome depending on the settings. Specifically, if multi-factor authentication that combines an IC card and a PIN is enabled, the user must swipe their IC card and enter their PIN every time they use the image forming device. Some people find the combination of IC card and PIN authentication cumbersome, while others do not.

[0007] The present invention has been made in consideration of the above-mentioned problems, and aims to improve convenience when performing multi-factor authentication while increasing security by allowing a user to select at least one of the authentication methods in the multi-factor authentication setting. [Means for solving the problem]

[0008] The present invention has been made in consideration of the above-mentioned problems, and provides an information processing device that authenticates a user in at least first authentication processing and second authentication processing, and permits the authenticated user to use at least one of a plurality of functions, the information processing device including: a control means that, when authenticating the user in at least the first authentication processing, controls the user to select an authentication method to be used in the first authentication processing; a display means for displaying a first authentication screen used in the first authentication process and a second authentication screen used in the second authentication process. With The first authentication screen displays an area for performing the first authentication process using a first authentication method and an area for performing the first authentication process using a second authentication method. An information processing device comprising: [Effects of the Invention]

[0009] By implementing the above-described means, the user can select at least one of the authentication methods in the multi-factor authentication settings, thereby enhancing security and improving convenience when performing multi-factor authentication. [Brief explanation of the drawings]

[0010] [Figure 1] A simplified diagram showing the system configuration [Figure 2] Hardware configuration diagram [Figure 3] A diagram showing the software configuration and data areas managed by the software [Figure 4] FIG. 10 is a diagram showing an example of an authentication screen provided by the image forming apparatus. [Figure 5] FIG. 10 is a diagram illustrating an authentication setting screen provided by the image forming apparatus. [Figure 6] Multi-factor authentication flow diagram [Figure 7] Policy confirmation flow diagram when displaying the second factor screen [Figure 8] Notification screen display flow diagram for different elements [Figure 9] Multi-factor authentication flow diagram when functional authentication is enabled DETAILED DESCRIPTION OF THE INVENTION

[0011] Hereinafter, the best mode for carrying out the present invention will be described with reference to the drawings and tables.

[0012] <System Configuration in this Embodiment> 1 is a simplified diagram showing the configuration of a system to which the present invention is applied. It includes an image forming device 100 that forms an image to perform authentication processing, an authentication screen 101 on which IC card authentication used for multi-factor authentication can be performed, an authentication screen 102 on which a PIN or pattern input used for multi-factor authentication can be performed, and a user named Alice 103 who is registered in a user database.

[0013] User Alice is a user who has already registered a PIN and pattern in the user database. Additionally, the image forming apparatus 100 shown in FIG. 1 is configured to perform multi-factor authentication by using IC card authentication as the first authentication factor and inputting a PIN or pattern as the second authentication factor. The selection operation for selecting an authentication method on the authentication screen 102 refers to the input operation for entering an authentication screen entry in either the PIN authentication or pattern authentication area. The authentication method may be confirmed by the selection operation for selecting an authentication method, and then the authentication screen corresponding to the selected authentication method may be displayed.

[0014] After IC card authentication, user Alice inputs a personal identification number or a pattern to complete authentication to the image forming apparatus 100, and becomes able to use the functions of the image forming apparatus 100.

[0015] The image forming device 100 defined in this specification is an information processing device with printer, copy, and scan functions, and has a function that allows IC card registration and editing of passwords, PIN numbers, and patterns using an authentication setting screen. Note that, although the image forming device 100 is described as an example in this embodiment, it is not necessarily limited to an image forming device 100 with a printer function, etc., and any information processing device that can achieve multi-function authentication may be used.

[0016] The authentication process that is displayed as selectable on the authentication screen 102 is determined based on an administrator setting, which will be described later. The administrator setting refers to a setting that is realized when a user with administrator authority logs in to the image forming apparatus 100 using a local screen of the image forming apparatus 100 or a remote screen of the PC 315 or the like.

[0017] This time, the case is shown in which authentication screen 102 has an area for PIN authentication and an area for pattern authentication. However, as long as the user can select the authentication method, the options are not limited to PIN authentication and pattern authentication. Furthermore, the display order of authentication screen 101 and authentication screen 102 is not important. Furthermore, as with authentication screen 102, authentication screen 101 may also allow the user to select the authentication method.

[0018] <Hardware Configuration of Image Forming Apparatus 100> 2 is a hardware configuration diagram of an embodiment of an image forming apparatus. The image forming apparatus 100 includes a printer 207, a copier 208, a scanner 209, and a document information reader 210 that reads information from scanned documents. The image forming apparatus 100 also includes an operation unit 201 that operates the image forming apparatus 100, a card reader 202 over which a card is swept when logging in, and a CPU 206 that controls these.

[0019] The printer 207 is a unit that realizes a receiving function, and performs processing to form an image according to a print job received from, for example, a PC 315 connected to the same network, a wired LAN 212, and output it on paper. The copier 208 and scanner 209 are units that realize a transmitting function, and perform processing to optically read an original image set in the scanner unit and output it on paper as image data.

[0020] The document information reading unit 210 reads information (barcode, QR code (registered trademark), and background pattern) embedded in a document scanned by the scanner 209 and stores the read information in the HDD 205 .

[0021] The CPU 206 dynamically controls various hardware components 201-202, 206-211 that make up the image forming apparatus 100, thereby enabling the implementation of various functions of the image forming apparatus 100. The CPU 206 sends signals to the various hardware components via a bus line, enabling mutual data communication with other hardware components. The operation unit 201 is a user interface that enables a user of the image forming apparatus 100 to use the printer 207, copier 208, and scanner 209. The operation unit 201 can also be operated as a touch panel. The card reader 202 is a unit that enables authentication using a card.

[0022] Next, the software configuration in this embodiment will be described with reference to FIG.

[0023] <Software Configuration of Image Forming Apparatus 100> 3 is a software configuration diagram of the image forming apparatus 100. The image forming apparatus 100 in FIG. 3 includes copy 301, scan 302, print 303, user authentication setting 304, and authentication service 305 as applications that run on a platform. The above-mentioned applications communicate with various control services via an application program interface (API) 314 to launch the applications. The various control services are a group of modules including a scanner control service 306, printer control service 307, operation unit control service 308, wired LAN control service 309, and authentication control service 310. The image forming apparatus 100 also includes a user DB 311 that stores user information, and a login context storage RAM 312 that stores the login context of a user who has logged in.

[0024] Copy 301, Scan 302, Print 303, Authentication Settings 304, and Authentication Service 305 provide a user interface that can be operated by the user.

[0025] The authentication service function 305 provides a local authentication service and a remote authentication service function for logging in to the image forming apparatus 100. In addition, the authentication service function 305 uses information in the user DB 311 to register new users, change user information, and manage logged-in users.

[0026] These settings relating to management of login users and various authentications can be set by logging in to the image forming apparatus 100 and then performing remote access from the authentication setting 304 or the PC 315 .

[0027] Each function of the above-described embodiments can be realized by a program written in a legacy programming language or an object-oriented programming language, such as assembly language, C, C++, Visual C++, Perl, Ruby, JAVA (registered trademark), JAVABeans, JAVABApplet, or JAVAScript, which are registered trademarks of Oracle Corporation, and can be stored on a device-readable recording medium and distributed.

[0028] FIG. 4 shows an example of an authentication screen provided by the image forming apparatus 100. <Card authentication service> The card authentication service is a service that executes authentication processing by touching the card reader 202 provided in the image forming apparatus 100. With a card authentication screen 401 displayed on the image forming apparatus 100, the user touches their own card to the card reader 202 provided in the image forming apparatus 100. The image forming apparatus 100 reads the card ID from the card reader 202. It queries the authentication destination database for the acquired card ID and searches for a card ID associated with the user account. If the search results show that the card ID is registered, it executes authentication processing using the registered user account. If the card ID read by the card reader 202 is not registered, it results in an authentication error, and the card authentication screen 401 is displayed again.

[0029] Furthermore, when using the card authentication service, the card ID is registered in advance in the authentication destination database. The card ID may be registered by directly inputting it into the operation unit 201 of the image forming apparatus 100, or by reading the card ID with the card reader 202. When registering the card, the user is prompted to input a user account and password into the image forming apparatus 100, which executes a user verification process. This user verification process identifies pre-registered user information (user account and password), and links the card ID to the identified user information. Since the database used in the user verification process is the same as the authentication destination database, if user information is not registered in the authentication destination database, a user verification error occurs and the card ID registration process is aborted.

[0030] If user authentication is successful, the user touches the card they wish to register to the card reader 202, which associates the user account with the card ID, and thereafter the user becomes able to use the card authentication service.

[0031] <User account authentication service> The user account authentication service is a service that authenticates a user by having the user input a user account and password via a local UI of the image forming apparatus 100 or a remote UI of the PC 315, a mobile device, or the like.

[0032] A user of the image forming apparatus 100 enters a user account (405) and password (406) in the text fields of an account authentication screen 402 displayed on the local UI and presses a login button 407. At this time, if the user account and password information are registered in the authentication destination database, the authentication process is successful and the image forming apparatus 100 becomes available for use. If the user account does not exist or if an inconsistency in the password input occurs, an authentication error is detected and the account authentication screen 402 is displayed.

[0033] When using the user account authentication service, authentication information is registered in the authentication database. Users who have administrator privileges can register authentication information.

[0034] <PIN authentication service> The PIN authentication service is an authentication service for logging in to the image forming apparatus 100 by inputting a PIN via the local UI of the image forming apparatus 100 or the remote UI of the PC 315 or mobile device.

[0035] In this embodiment, it is assumed that IC card authentication will be used in combination, and therefore the authentication flow and user registration process are the same as those for the user account authentication service. The PIN entered on the PIN entry screen 403 may be the same as the password on the account authentication screen 402, or when a job is submitted to the image forming apparatus 100 from the PC 315, the PIN issued by the image forming apparatus 100 and displayed on the screen of the PC 315 may be entered on the password entry screen 403. The PIN in this case is assumed to have a set expiration date.

[0036] <Pattern authentication service> The pattern authentication used in this embodiment will be described. For pattern authentication, a pattern lock mechanism that operates on the Android OS, a registered trademark of Google Inc., is adopted. The user registers the pattern to be used for pattern authentication in advance in the authentication settings 304, and inputs the pattern trajectory on the touch panel of the image forming apparatus 100 by tracing the dots drawn on the pattern input screen 404. At least a portion (multiple) of the drawn dots shall be used. If the pattern trajectory matches the registered pattern, the functions of the image forming apparatus 100 can be used. If it does not match the registered pattern, an authentication error occurs and the pattern input screen 404 is displayed.

[0037] The pattern authentication process is started when the user finishes inputting the pattern and removes his / her finger from the touch panel.

[0038] Furthermore, for pattern points, numbers such as those shown on the pattern input screen 404 are held internally (the numbers are not displayed on the screen), and when registering a pattern in the user database, the array number of the pattern points is managed and saved in the user database.

[0039] <User information registered in the database> Table 1 below shows the user information registered in the authentication database.

[0040] [Table 1]

[0041] The "user name" and "password" in Table 1 are referenced during the authentication process of the above-mentioned <user account authentication service> and the registration process of the <card authentication service>. The "card ID" in Table 1 is referenced during the authentication process of the <card authentication service>. The "PIN" and "pattern" are referenced when the <PIN authentication service> and <pattern authentication service> are executed. Furthermore, if the image forming device 100 is configured for multi-factor authentication, it is assumed that the "pattern" or "PIN" will be referenced when executing the second-factor authentication process, which is entered after the card authentication service is executed. The "image forming device usage authority" in Table 1 indicates user authority information, and users with administrator authority can set the authentication method using the method described below (Figure 5).

[0042] <Function-specific authentication> When using the device, the image forming device 100 displays an authentication screen as shown in Fig. 4, and provides the user with two modes: a device authentication mode in which the functions of the image forming device 100 cannot be used unless the authentication process is successful, and a function-specific authentication mode in which an authentication screen is displayed when using an application held by the image forming device 100. In the function-specific authentication mode, authentication is performed for each application, so the administrator user can set the mode so that, for example, authentication process is performed for copying, but printing can be used without performing authentication process.

[0043] The multi-factor authentication described in this embodiment is assumed to be used in device authentication mode or function-specific authentication mode. Therefore, the settings on an authentication setting screen 501 (described later) are applied during device authentication when the image forming apparatus 100 is in device authentication mode, and are applied during function-specific authentication when the image forming apparatus 100 is in function-specific authentication mode.

[0044] <Authentication settings screen> An authentication setting screen 501 provided in the image forming apparatus 100 will be described with reference to FIG.

[0045] The authentication setting screen 501 is configured with authentication setting screens 501 related to multi-factor authentication used in each authentication service.

[0046] Whether multi-factor authentication is applied to the image forming apparatus 101 (enabled or disabled) is determined by the setting in setting item 502. It is also possible to set whether multi-factor authentication applies to "all users" or "administrator only" (502). If the multi-factor authentication setting is set to "all users," it is applied to all users registered in the database referenced by the image forming apparatus 100. If the multi-factor authentication setting is set to "administrator only," the multi-factor authentication setting is applied only to administrator users, and other users are authenticated using only one-factor authentication processing. Specifically, when the image forming apparatus 100 performs first-factor authentication, it checks the user's authority information from the user database shown in Table 1. If the user is an administrator, it displays the second-factor authentication screen 102 and performs multi-factor authentication. In this case, if the user is a general user, the authentication screen 102 is not displayed, and the first-factor authentication processing determines whether the user is allowed to use the image forming apparatus 100.

[0047] If the multi-factor authentication setting is set to "All users" or "Administrator only," PIN authentication or pattern authentication can be set as the second factor. Password authentication, for example, may be made selectable as the second factor, as an item not shown in Figure 5.

[0048] It is also possible to set up the system so that users can choose between PIN authentication or pattern authentication as the second-factor authentication method. Figure 5 shows the state when this setting has been made. PIN authentication and pattern authentication are displayed as multiple authentication method options. The "PIN" and "Pattern" checkboxes are filled in, indicating that both are selected as second-factor authentication methods. This means that the second-factor authentication method can be selected as shown on authentication screen 102 in Figure 1. In addition, as a setting item for pattern authentication, the administrator can specify the dot arrangement as a 3x3 pattern arrangement, a 4x4 pattern arrangement, or a 5x5 pattern arrangement. The authentication screen for pattern authentication is displayed based on the settings.

[0049] If you want to fix the second factor authentication method to either PIN or pattern authentication, check the checkbox for the appropriate authentication method and leave the checkbox for the other authentication method unchecked.

[0050] Second Factor Policy Settings 504 is a policy setting item for the second factor of multi-factor authentication. Set the policy for the factor selected in Authentication 503 to be used for multi-factor authentication. If PIN is enabled (the "PIN" checkbox is filled in), it is possible to set a policy for using PIN, prohibiting the use of PINs registered in the user database with a specified number of digits or less. If pattern is enabled (the "Pattern" checkbox is filled in), it is possible to prohibit patterns with a specified number of dots or less. For example, if pattern points of 4 or less are prohibited, the user name Dave, which has a pattern point of 4 or less as shown in Table 1, will not be able to use pattern authentication.

[0051] If the policy setting for pattern authentication is "Prohibit English characters," patterns whose pattern trajectory is written in English are prohibited. For example, the pattern for user "Alice" is "14789" (Table 1), but if the number of dots is 3 x 3, this becomes the pattern of the English letter "L," so pattern authentication is not possible.

[0052] "Two-factor setting for function-specific authentication" 505 can be set only when function-specific authentication mode is enabled, and allows you to set the authentication method that can be used for each application. In the example shown in Figure 5, when using a print application, "pattern prohibition" is set, so multi-factor authentication can be performed using an authentication method other than pattern authentication. For copy applications, there are no particular restrictions on the authentication methods that can be used.

[0053] 5 shows an example in which the first-factor authentication method is fixed and the second-factor authentication method is set to be selected by the user, but it is also possible to set it so that the user is allowed to select only the first factor, or so that the user is allowed to select both factors. Also, in this embodiment, the case where there are two authentication factors is described, but if there are three or more authentication factors, the user may be allowed to select the authentication method for at least one of the factors.

[0054] <Explanation of the flow according to the present invention> Next, a flow in which the CPU of image forming apparatus 100 loads a program stored in ROM 203 into RAM 204 and executes the program will be described using the flowchart in Fig. 6. Also, Fig. 6 describes an example of a multi-factor authentication flow in which a <card authentication service> can be set as the first factor and a <personal identification number service> and a <pattern authentication service> can be set as the second factor when multi-factor authentication is performed, but as described above, the combination, number, and order of the factors are not particularly important.

[0055] <Multi-factor authentication flow> The multi-factor authentication flow for a user who has already registered with the image forming apparatus 100 is shown below.

[0056] When performing multi-factor authentication, the image forming apparatus 100 displays the IC card authentication screen 401, which corresponds to the first factor (S600). After executing an IC card authentication request (S601), the image forming apparatus 100 performs authentication processing using the IC card information, and if the IC card information is registered in a database referenced by the image forming apparatus 100, the authentication is successful, but if the IC card information is not registered, the authentication is considered unsuccessful and the display of the IC card authentication screen 401 continues (S602). If the authentication is successful, the user information of the authenticated user is obtained from the database (S602).

[0057] The image forming apparatus 100 refers to the information set on the authentication setting screen 501 and checks whether multi-factor authentication is enabled (S603). If multi-factor authentication is enabled, it refers to the user information acquired in S602. If the authority information in the user information is "administrator" (S604), it refers to the setting value of the second-factor authentication method in the authentication settings shown in "Authentication to be used for multi-factor authentication" 503 and checks whether a PIN and pattern have been set (S608). If both the PIN and pattern are valid, the image forming apparatus 100 checks whether the PIN and pattern have been registered in the user database from the user information acquired in S602 (S612).

[0058] If the user is a registered user, the image forming apparatus displays the authentication screen 102 (FIG. 1) on which both a personal identification number and a pattern can be entered (S615).

[0059] If the result of the determination in S608 is that only a PIN is valid as the second-factor authentication method (S613) or only a pattern is valid (S614), an authentication screen that allows the respective registered second-factor authentication method to be executed is displayed (403 or 404).

[0060] If both the PIN and the pattern are invalid, a second-factor registration error screen (not shown) is displayed, and the process ends (S618). In this embodiment, if the multi-factor authentication setting is enabled and both second-factor authentication methods are disabled, an error screen is displayed. However, if the multi-factor authentication setting is enabled but no second-factor authentication method is selected during the setup process on the authentication setting screen 501 of FIG. 5, an error message may be displayed, or the authentication setting screen 501 may not be closed unless a second-factor authentication method is selected.

[0061] After displaying the authentication screen (S615 to 617, S606 to 607), the image forming apparatus 100 displays the authentication screen to accept the second factor authentication process (S619).

[0062] After the authentication process is completed, the image forming apparatus 100 generates a login context for the authenticated user and ends the process (S620). If an error occurs in the authentication process of S619, an authentication screen corresponding to the process content of each of S615 to S617 is displayed, and the user is prompted to re-enter authentication information.

[0063] Once the two-factor authentication process is complete, the functions provided by image forming apparatus 100 can be used. For example, a menu screen (not shown) for selecting a copy function, a scan function, or the like of the image forming apparatus may be displayed. Alternatively, if a setting screen for a specific function is set as the initial screen, the setting screen may be displayed once the two-factor authentication process is complete.

[0064] If the authority information from the user information acquired in S602 indicates a general user (No in S604), the image forming apparatus 100 refers to the setting shown in 502 to check whether the user applicable to multi-factor authentication is "administrator only" or "all users" (S605). If the result of the reference indicates that "all users" are subject to multi-factor authentication, the image forming apparatus 100 executes the same multi-factor authentication process as for the administrator user (S608 onward). If the subject user is "administrator only," the "authentication flow when multi-factor authentication is not set" (S606 to S607), which will be described later, is executed.

[0065] <Multi-factor authentication flow when there is only one second-factor authentication method> The image forming apparatus 100 checks the second factor authentication method from the authentication setting screen 501 (S608). If the setting of only a PIN is valid as the second factor authentication method (S609), the image forming apparatus 100 checks from the acquired user information whether the user has set a PIN (S611).

[0066] If the user has registered a PIN, the PIN entry screen 403 is displayed (S616). If the user has not registered a PIN, a second factor registration error screen (S618) is displayed, and the process ends.

[0067] If the result of the determination in S608 to S609 is that the pattern-only setting is valid as the second-factor authentication method (S610), the pattern input screen 404 is displayed (S617). If the user has not registered a pattern, a second-factor registration error screen (S618) is displayed, and the process ends.

[0068] <Authentication flow when multi-factor authentication is not configured> If it is determined in S603 that the multi-factor authentication setting is not enabled, it is determined from the user information acquired in S602 whether the user has registered second-factor authentication information (S606). If the user has registered one or more second-factors, an authentication screen for the registered factors is displayed (S607). If the second-factors are not registered, authentication processing is performed using the user information acquired in the IC card authentication request (S601), and a login context for the authenticated user is generated (S620), thereby executing login processing. It is also possible to display a default authentication screen and create a user context without performing the processing of S606.

[0069] Next, a flow for confirming a policy when displaying the second-factor authentication screen in steps S615 to S617 will be described with reference to Fig. 7. Note that the flow in Fig. 7 is assumed to be performed in steps S615 to S617.

[0070] <Policy confirmation flow when displaying the second factor screen> After the user information acquisition process and the second-factor authentication screen are determined from the authentication setting screen 501 (S701), the image forming apparatus 100 refers to the second-factor policy setting 504 (S702). If the policy setting is not valid (no policy setting has been made), the image forming apparatus 100 displays the second-factor authentication screen and ends the process. If the policy setting is valid (policy setting has been made), the image forming apparatus 100 refers to the authentication information registered in the user's second factor in the authentication database and checks whether the second-factor authentication information satisfies the policy (S703). If the policy is not satisfied, the process proceeds to S704. If the policy is satisfied, the image forming apparatus 100 displays the second-factor input screen (S707).

[0071] A specific method for determining whether the policy settings are valid in S702 will be described. A PIN authentication policy and a pattern authentication policy are set in the policy settings 504. However, the type of authentication method used in each of steps S615 to S617 differs. In S615, PIN authentication and pattern authentication are used, in S616, only PIN authentication is used, and in S617, only pattern authentication is used. The policy settings 504 corresponding to the authentication method used in each step is referenced in S702. For example, in the case of S615, both the PIN authentication policy and the pattern authentication policy are referenced in S702.

[0072] If it is determined in S703 that the user's second-factor authentication information does not satisfy the policy, other authentication information registered in the authentication database as the user's second factor is referenced. Then, it is determined whether the authentication information satisfies the policy (S704). For example, if it is determined in S612 that the user has a PIN and pattern set, it is determined in FIG. 7 whether to display the authentication screen 102, which has both a PIN input area and a pattern input area. If it is determined in S703 that the user's PIN registered in the authentication database does not satisfy the policy, it is then determined in S704 whether the user's pattern registered in the authentication database satisfies the policy.

[0073] If it is determined in S704 that the registered authentication information does not satisfy the policy, an error is displayed in S706. If it is determined that the registered authentication information satisfies the policy, a second-factor authentication screen is displayed in S707 and the process ends. For example, if it is determined in S704 that the user's pattern registered in the authentication database satisfies the policy, pattern input screen 404 is displayed. If it is determined in S704 that the policy is not satisfied, an error is displayed. In other words, even if it is determined in S612 that the user has a PIN and pattern set, authentication screen 102 is not necessarily displayed as the second-factor authentication screen, and the display content of the second-factor authentication screen will differ depending on the determination results of S703 and S704.

[0074] Furthermore, whether or not to execute the process of S704 will differ depending on the settings of S612 and S614. If the determination result of S612 or S614 limits the second-factor authentication method to one (for example, only pattern authentication or only password number authentication), there is only one piece of authentication information to be determined in Fig. 7 to determine whether the policy is satisfied. Therefore, if it is determined in S703 that the policy is not satisfied, the process proceeds to S706 without executing S704 and ends. This concludes the explanation of Fig. 7.

[0075] The flow for notifying the element to be displayed after accepting the second factor authentication process in S619 is described below.

[0076] <Notification screen display flow for other elements> This flow can be executed when the setting of the PIN and pattern is valid as the second factor authentication means (S608).

[0077] After confirming that the PIN and pattern settings are valid as second-factor authentication means (S801), the image forming apparatus 100 accepts the second-factor authentication process (S802) and checks the elements registered as second-factor authentication information from the acquired user information. If the result of the check shows that the user has only one element, either a PIN or a pattern, registered as authentication information (S803), the image forming apparatus 100 notifies the user that they can add another element to their authentication information after the second-factor authentication process (S805).

[0078] The notification in S805 is a function that is executed when the user logs in for the first time; in S804, it is determined whether it is the first login, and if it is determined to be the second or subsequent login, no notification is given and only the authentication process is executed. The processing content of S806 is the same as S620, so a description thereof will be omitted. The above is the flow related to the notification of the element to be displayed after the second-factor authentication process is accepted in S619.

[0079] As described in <Function-Specific Authentication>, the image forming apparatus 100 can select between the device authentication mode and the function-specific authentication mode. The multi-factor authentication flow when function-specific authentication is enabled will be described with reference to FIG.

[0080] <Multi-factor authentication flow when functional authentication is enabled> When explaining this flow, it is assumed that the second authentication factor on the authentication setting screen 501 is a valid PIN and pattern, and that the device user is an administrator who has registered the PIN and pattern.

[0081] The image forming apparatus 100 detects that the application button has been pressed (S901).

[0082] When an application button is selected, the image forming apparatus 100 checks whether the application designated by pressing the application button is subject to function-based authentication (S902). If the application is not subject to function-based authentication, the process ends without displaying the authentication screen.

[0083] If the function-specific authentication is required, the image forming apparatus 100 performs a process to display an IC card authentication screen (S903). After the display process, the image forming apparatus 100 accepts an IC card authentication request (S904), and after the first-factor authentication process, it performs a process to display an authentication screen for the second factor (S905). Whether IC card authentication is adopted in the first-step authentication depends on the setting contents of the authentication 503 on the authentication setting screen 501, as described above.

[0084] The two-factor setting 505 for function-specific authentication is referenced to check which two-factors are permitted for the specified application (S906).

[0085] If both a PIN and a pattern are permitted as elements that can be specified as the second element, processing is performed to display the authentication screen 102 that allows input of a PIN and a pattern (S909). If only a PIN is permitted (S907), the PIN input screen 403 is displayed (S910), and if only a pattern is permitted (S908), the pattern input screen 404 is displayed (S911).

[0086] After the second-factor authentication screen is displayed (S909 to S911), the image forming apparatus 100 accepts the second-factor authentication process (S912) and generates a login context for the authenticated user (S913). This completes the display process of the authentication screen in the function-specific authentication mode.

[0087] According to the above embodiment, when performing multi-factor authentication, the user can select the authentication process to be used for the second factor within the range set by the administrator. As a result, the user can adopt the desired authentication method for the second factor authentication method, thereby improving usability during multi-factor authentication.

[0088] [Other Examples] The present invention can also be realized by executing the following process. That is, software (program) that realizes the functions of the above-described embodiments is supplied to a system or device via a network or various storage media, and the computer (or CPU, MPU, etc.) of the system or device reads and executes the program. In this case, the computer program and the storage medium storing the computer program constitute the present invention. [Explanation of symbols]

[0089] 100 Image forming device 102 Authentication screen 501 Authentication setting screen

Claims

1. An information processing device that authenticates a user in at least first authentication processing and second authentication processing, and permits the authenticated user to use at least one function among a plurality of functions, a control means for controlling the user to select an authentication method to be used in the first authentication process when authenticating the user in at least the first authentication process; a display means for displaying a first authentication screen used in the first authentication process and a second authentication screen used in the second authentication process; an information processing device, characterized in that the first authentication screen displays an area for performing the first authentication process using a first authentication method, which is pattern authentication, and an area for performing the first authentication process using a second authentication method.

2. The control means 2. The information processing apparatus according to claim 1, wherein, when authenticating the user in at least the first authentication process, the information processing apparatus controls the user to select an authentication method to be used in the first authentication process on the first authentication screen.

3. At least one of the plurality of functions is 3. The information processing apparatus according to claim 1, wherein the function is a copy function.

4. a plurality of dots are drawn in the area for performing the first authentication method, 4. The information processing apparatus according to claim 3, wherein the first authentication method is a method in which the user selects at least some of the dots from among the plurality of dots, and authentication is performed based on a combination of the selected dots.

5. 5. The information processing apparatus according to claim 1, further comprising a setting unit for setting an authentication method to be used in the first authentication process.

6. The setting means 6. The information processing device according to claim 5, wherein a plurality of authentication methods selectable in the first authentication process are displayed as options, and when pattern authentication is included in the options, the number of dots to be used in the pattern authentication is displayed so that it can be set.

7. 7. The information processing apparatus according to claim 6, wherein the settings made by said setting means can be set by a user having administrator authority.

8. 8. The information processing apparatus according to claim 7, wherein, when the user is authenticated by the second authentication process using the second authentication screen, the first authentication screen is displayed, and the user is authenticated by the first authentication process.

9. The information processing device has a plurality of functions, 9. The information processing apparatus according to claim 1, wherein, when user authentication by the first authentication process and the second authentication process is completed, a menu screen for selecting the plurality of functions is displayed.

10. A control method for an information processing device that authenticates a user in at least a first authentication process and a second authentication process, and allows the authenticated user to use at least one function out of a plurality of functions, a control step of controlling the user to select an authentication method to be used in the first authentication process when authenticating the user in at least the first authentication process; a display step of displaying a first authentication screen used in the first authentication process and a second authentication screen used in the second authentication process; A control method for an information processing device, characterized in that the first authentication screen displays an area for performing the first authentication process using a first authentication method, which is pattern authentication, and an area for performing the first authentication process using a second authentication method.

11. A program for causing an information processing device to execute the control method described in claim 10.

Citation Information

Patent Citations

  • Information processing device, control method and program

    JP2015170117A

  • Authentication system and method

    JP2016045811A

  • Image formation device, authentication method of image formation device, program and print system

    JP2019155610A

  • Secure two-factor authentication for mobile devices

    JP2019515366A

  • Authentication system and authentication method

    JP2020166597A