Image forming device
The image processing device addresses authorization method limitations by supporting multiple authorization methods and providing fallback options, ensuring uninterrupted operations and user-friendly authorization processes.
Patent Information
- Application Number
- JP2025107132
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2025-06-25
- Publication Date
- 2026-01-15
- Estimated Expiration
- 2044-02-26
AI Technical Summary
Existing image processing devices face challenges in authorization processing due to limitations in supported authorization methods, leading to potential hindrances and user confusion when service providers do not support the device flow method, especially when the browser function is unavailable.
The image processing device is equipped with a control unit that determines the support for selected authorization methods and restricts execution if unsupported, prompting the user to select an alternative method, thereby supporting multiple authorization methods like OAuth flow and device flow.
This approach ensures seamless authorization processing by reducing the risk of method-related failures and enhancing user experience by providing fallback options, ensuring continuous authorization operations.
Smart Images

Figure 0007799886000001 
Figure 0007799886000002 
Figure 0007799886000003
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an image processing device and the like. [Background technology]
[0002] As an authorization method for using resources, a more secure authorization method using the OAuth protocol or the like has become mainstream (for example, Patent Document 1).
[0003] As an authorization method based on the OAuth protocol, a device flow method is known in which authorization is granted to an image processing device such as a multifunction peripheral via an external terminal device such as a PC (Personal Computer) or a smartphone via the Web.
[0004] The device flow method allows authorization of an image processing device without being restricted by whether the image processing device is equipped with a browser or by the input means for inputting authorization and authentication information.
[0005] However, some service providers that provide OAuth authorization services do not support the device flow method, and authorization processing using the device flow method cannot be performed. [Prior art documents] [Patent documents]
[0006] [Patent Document 1] Patent Publication No. 2021-152835 Summary of the Invention
[0007] The present disclosure aims to provide an image processing device and the like that can reduce the risk that the implementation of authorization processing will be hindered due to the authorization method applied. [Means for solving the problem]
[0008] In order to solve the above problem, an image processing device according to the present disclosure includes a control unit capable of performing authorization processing using a plurality of authorization methods for an authorization server, a storage unit that stores connection information for the authorization server, and an output unit that outputs screen information related to the authorization processing, wherein when a user selects the authorization processing based on one authorization method using the connection information, the control unit determines whether the authorization server supports the one authorization method, and when the authorization server determines that it does not support the one authorization method, restricts the execution of the authorization processing using the one authorization method, and the output unit outputs a notification urging the user to select an authorization method different from the one authorization method.
[0009] Furthermore, an authorization method in an image processing device according to the present disclosure is an authorization method in an image processing device that is capable of performing authorization processing using a plurality of authorization methods for an authorization server, and when a user selects the authorization processing based on one authorization method, the authorization server determines whether or not the one authorization method is supported, and when the authorization server determines that the one authorization method is not supported, restricts the execution of the authorization processing using the one authorization method and outputs a notification urging the user to select another authorization method different from the one authorization method. [Effects of the Invention]
[0010] According to the present disclosure, it is possible to provide an image processing device or the like that can reduce the risk that the authorization process will not be realized due to the authorization method applied. [Brief explanation of the drawings]
[0011] [Figure 1] 2 is a diagram illustrating a connection configuration between a service server and an external terminal device for a multifunction peripheral according to the first embodiment. FIG. [Figure 2] FIG. 2 is a diagram illustrating the functional configuration of the multifunction peripheral according to the first embodiment. [Figure 3] FIG. 10 is a diagram illustrating a setting information table. [Figure 4]1 is a flowchart illustrating a processing flow according to the first embodiment. [Figure 5] FIG. 1 is a diagram illustrating an authorization flow method and a device flow method. [Figure 6] FIG. 2 is a diagram illustrating an example of operation according to the first embodiment. [Figure 7] FIG. 2 is a diagram illustrating an example of operation according to the first embodiment. [Figure 8] 10 is a flowchart illustrating a processing flow according to the second embodiment. [Figure 9] FIG. 10 is a diagram illustrating an example of operation according to the second embodiment. [Figure 10] FIG. 10 is a diagram illustrating an example of operation according to the third embodiment. [Figure 11] FIG. 10 is a diagram illustrating an example of operation according to the third embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0012] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. In this disclosure, a multifunction peripheral capable of performing jobs related to copying, faxing, email, etc. in a single housing will be described as one form of an image processing device according to the present disclosure. Note that the following embodiment is an example for explaining the present disclosure, and the technical content of the description set forth in the claims is not limited to the following description.
[0013] In addition to the device flow method described above, an authorization flow method is also known as an authorization method based on the OAuth protocol, in which authorization processing is performed using a browser installed in the image processing device itself. If it is difficult to implement authorization processing using the device flow method, the authorization flow method can be performed on the image processing device itself, which is thought to be advantageous for users because it allows the authorization processing to continue.
[0014] Therefore, for example, when authorization processing is performed from the image processing device itself, the authorization flow method is applied, and when authorization processing is performed using settings via the Web, the device flow method is applied. In this way, by making it possible to perform authorization processing that supports multiple different authorization methods with a single image processing device, it is expected that the throughput related to authorization processing will be dramatically improved.
[0015] However, with the above configuration, the service providers that can be used may differ depending on which method is used to execute the authorization process. Furthermore, if the browser included in the image processing device becomes unavailable due to factors such as the state of the image processing device itself or the expiration date of the service provider's support, the authorization process may become unable to be executed using the authorization flow method. In this way, the inability to execute the authorization process due to the state, setting method, or setting contents of the image processing device may cause confusion for users.
[0016] The present disclosure provides an image processing device or the like that can reduce the risk that the authorization process will not be performed due to the authorization method applied, in the following embodiments.
[0017] [1 First Embodiment] In the first embodiment, the form of a multifunction device 10 will be described as one form of image processing device, but the image processing device may be a printer, copier, fax machine, etc. that has limited job functions of various types other than the multifunction device 10.
[0018] [1.1 Connection type] FIG. 1 is a diagram illustrating an example of a connection between a service server 30 (30a, 30b, ...) and an external terminal device 50 with respect to a multifunction peripheral 10. The multifunction peripheral 10 is connected to the service server 30 (30a, 30b, ...) and the external terminal device 50 via a network NW so as to enable mutual communication between them. Note that the multifunction peripheral 10 according to the present disclosure can also function as a server device capable of outputting screen information relating to job execution, various settings, authorization processing, etc., as a Web-User Interface (UI) to the external terminal device 50 or its own browser via, for example, a Web application using a communication protocol such as HTTP (HyperText Transfer Protocol) or a native application (not shown).
[0019] The service servers 30 (30a, 30b, ...) are authorization servers that are capable of executing authorization processing using at least either the authorization flow method or the device flow method, or both, based on the OAuth protocol. Here, lowercase letters ("a", "b") represent service servers 30 with different service specifications (e.g., supported authorization method, whether a browser is required, settings, etc.). Furthermore, the service servers 30 are not limited to two service servers 30a and 30b, but may include two or more service servers 30. In the present disclosure, when there is no need to distinguish between the service servers 30a and 30b, they may be simply referred to as the service servers 30.
[0020] The external terminal device 50 is an information processing device that can control the multifunction device 10 via the Web (application). The external terminal device 50 can perform operations related to job execution, various settings, authorization processing, etc. on the multifunction device 10 based on screen information output from the multifunction device 10 functioning as a server device. In particular, the external terminal device 50 can accept input of authentication information by a user and perform authentication processing with the service server 30 in authorization processing in the device flow method.
[0021] [1.2 Functional Configuration] [1.2.1 About the Multifunction Device 10] The functional configuration of the multifunction device 10 will be described with reference to Fig. 2. The multifunction device 10 includes a control unit 11, a display unit 13, an operation input unit 15, a communication unit 17, an image processing unit 19, and a storage unit 21.
[0022] The control unit 11 controls the entire multifunction device 10. The control unit 11 can be configured with one or more processing devices (for example, a CPU (Central Processing Unit), an SoC (System On Chip), etc.). The control unit 11 realizes its functions by reading out various programs stored in the storage unit 21.
[0023] The display unit 13 is a display device that displays various information to the user. The display unit 13 can be configured, for example, with an LCD (Liquid Crystal Display), an organic EL (Electro-Luminescence) display, etc. Based on the control of the control unit 11, the display unit 13 displays screen information such as a home screen (not shown), a setting screen for executing each job, and an authorization process, via a browser screen (described later).
[0024] The operation input unit 15 is an input device that accepts information input by a user or the like. The operation input unit 15 can be configured with various input devices, such as operation keys such as hardware keys or software keys, buttons, etc. The operation input unit 15 can also be configured as a touch panel that allows input via a display device such as an LCD (Liquid Crystal Display) or an organic EL (Electro-Luminescence) display. When the operation input unit 15 is configured as a touch panel (hereinafter, sometimes referred to as an operation panel), coordinate information, pressure-sensitive information, etc. on the operation panel can be acquired. In this case, the input method of the touch panel can be, for example, a common method such as a resistive film method, an infrared method, an electromagnetic induction method, or a capacitance method.
[0025] The communication unit 17 includes a wired / wireless interface or both for communicating with the service server 30 and the external terminal device 50 via a network NW such as a LAN (Local Area Network), a WAN (Wide Area Network), the Internet, a telephone line, or a FAX line. Furthermore, the communication unit 17 may include an interface related to wireless communication technology such as Bluetooth (registered trademark), NFC (Near Field Communication), Wi-Fi (registered trademark), IrDA (Infrared Data Association), or wireless USB (Universal Serial Bus).
[0026] Image processing unit 19 includes image forming unit 191 and image input unit 193. Image forming unit 191 feeds paper from a paper feed unit (not shown), forms an image on the paper based on image data, and then discharges the paper to a paper discharge unit (not shown). Image forming unit 191 can be configured, for example, by a laser printer that employs an electrophotographic method. In this case, image forming unit 191 forms an image using toner supplied from toner cartridges (not shown) that correspond to toner colors (for example, cyan, magenta, yellow, and black).
[0027] The image input unit 193 generates image data by scanning an original. The image input unit 193 can be configured as a scanner device equipped with an image sensor such as a CCD (Charge Coupled Device) or a CIS (Contact Image Sensor), as well as an automatic document feeder (ADF) and a flatbed for placing and reading an original. The image input unit 193 is not particularly limited in configuration as long as it is configured to be able to read reflected light from an original image using an image sensor. The image input unit 193 can also be configured as an interface capable of acquiring image data stored in a storage medium such as a USB memory or image data transmitted from an external terminal device 50. The image processing unit 19 may be configured to perform, for example, shading correction or density correction on the image data input from the image input unit 193 to generate image data for image transmission.
[0028] The storage unit 21 is one or more storage devices that store various programs and various data required for the operation of the multifunction peripheral 10. The storage unit 21 can be configured with storage devices such as RAM (Random Access Memory), SSD (Solid State Device), HDD (Hard Disk Drive), and ROM (Read Only Memory).
[0029] In the first embodiment, the storage unit 21 stores a control program 211, an authorization program 213, a browser program 215, and a server program 217, and reserves a setting information storage area 219.
[0030] The control program 211 is a program that is read by the control unit 11 when controlling the entire multifunction device 10. The control unit 11 that reads the control program 211 functions as an OS (Operating System) and controls the operation of hardware such as the display unit 13, operation input unit 15, communication unit 17, and image processing unit 19.
[0031] The authorization program 213 is a program that is read by the control unit 11 when performing authorization processing with the service server 30. After reading the authorization program 213, the control unit 11 can request the acquisition of an authorization code or an access token issued by the service server 30, and can request a resource by presenting the acquired access token.
[0032] The authorization program 213 includes an authorization method determination program 2131, an authorization information acquisition restriction program 2133, and a notification output program 2135. The control unit 11 that reads out the authorization method determination program 2131 determines whether or not authorization processing using the authorization method selected by the user is executable. The control unit 11 that reads out the authorization method determination program 2131 can determine whether or not authorization processing using the authorization method is executable, for example, based on whether or not the authorization destination service server 30 supports the authorization method selected by the user.
[0033] When it is determined that the authorization process using the authorization method selected by the user cannot be executed, the control unit 11 reads out the authorization information acquisition restriction program 2133. After reading out the authorization information acquisition restriction program 2133, the control unit 11 restricts the execution of the authorization process using that authorization method. In this case, for example, the control unit 11 restricts the acquisition (request) of authorization information by hiding a selection button that accepts an acquisition request for authorization information such as an authorization code or an access token from the service server 30, or by graying out the selection button, making the selection button unselectable.
[0034] Furthermore, when it is determined that the authorization process using the authorization method selected by the user cannot be executed, the control unit 11 reads out the notification output program 2135. The control unit 11 that reads out the notification output program 2135 functions as an output unit, restricts the execution of the authorization process using the authorization method, and outputs a notification urging the user to select an authorization method other than the authorization method. Note that when it is determined that the authorization process using the authorization method selected by the user cannot be executed, the control unit 11 may first read out the notification output program 2135, output a notification urging the user to select an authorization method other than the authorization method, and then restrict the acquisition of authorization information by reading out the authorization information acquisition restriction program 2133.
[0035] Browser program 215 is a program that is read by control unit 11 when rendering screen information and displaying a screen for viewing on display unit 13. In the following description, the function realized by control unit 11 that reads browser program 215 may be simply referred to as a browser. The browser can display notifications, etc. output by notification output program 2135, via a browser screen displayed on display unit 13.
[0036] The server program 217 is a program that the control unit 11 reads out when providing screen information in response to a request from a browser. The control unit 11 that reads out the server program 217 can realize a server function of outputting screen information in response to a request from the browser of its own device or a browser equipped in the external terminal device 50.
[0037] The setting information storage area 219 is a storage area that stores setting information related to device settings of the multifunction device 10. An example of the setting information stored in the setting information storage area 219 will now be described with reference to Fig. 3. Fig. 3 is an example of a setting information table that manages the setting information stored in the setting information storage area 219 on a setting item basis. Note that the setting information stored in the setting information storage area 219 may be managed in a database format other than a table format.
[0038] 3 is an example of setting items selected from connection settings, browser settings, and provided services (service settings). In addition to these setting items, the setting information table can also manage setting information related to hardware settings, system settings, etc.
[0039] The connection settings are, for example, setting items related to connection information for connecting to a terminal device or service located on the network NW, such as the service server 30. Here, ID is an identifier for uniquely identifying the connection information. For example, the connection information identified by ID "001" is connection information including settings such as the protocol "OAuth," the provider "provider aaa," the response type "Code," the client ID "aabbcc," and the redirect URL "https: / / aabbcc.com." Note that the connection information identified by ID "001" is an example of a request parameter included in an authorization request of the authorization flow method. When the authorization method is the authorization flow method, the control unit 11 transmits an authorization request based on these request parameters to the authorization endpoint of the service server 30.
[0040] The connection information identified by ID "002" includes settings such as the protocol "OAuth," the provider "provider aaa," and the client ID "aabbcc." The connection information identified by ID "002" is an example of a request parameter included in an authorization request in the device flow scheme. When the authorization scheme is the device flow scheme, the control unit 11 transmits an authorization request based on these request parameters to the authorization endpoint of the service server 30.
[0041] The connection settings may include connection information related to protocols other than the OAuth protocol. For example, the connection information identified by the ID "00N" is an example of connection information related to the SMTP protocol.
[0042] The browser setting is setting information that defines whether the browser function of the multifunction device 10 is enabled or disabled. In the first embodiment, if the value of the browser setting is "Yes", it indicates that the browser function is enabled, and if the value of the browser setting is "No", it indicates that the browser function is disabled.
[0043] The provided services (service settings) are setting items that define the authorization services that can be provided by the service server 30, which is a provider. For example, the service server 30a functioning as the provider aaa can provide authorization services using both the authorization flow method and the device flow method (Authorization Flow_Yes, Device Flow_Yes). On the other hand, the service server 30b functioning as the provider bbb can provide authorization services using the authorization flow method (Authorization Flow_Yes), but cannot provide authorization services using the device flow method (Device Flow_No).
[0044] The control unit 11 that reads the authorization method determination program 2131 can determine whether authorization processing using the authorization method selected by the user can be executed by referring to the setting items (service settings) stored in the setting information storage area 219.
[0045] [1.2.2 Service Server 30 (30a, 30b,...)] The service server 30 can use any known configuration as long as it is capable of executing authorization processing using at least either the authorization flow method or the device flow method, or both, based on the OAuth protocol. Therefore, a description of the functional configuration of the service server 30 will be omitted. Note that, although FIG. 1 illustrates the configuration of the service server 30 (30a, 30b, ...) as a standalone device configuration capable of providing authorization services, it is also possible to configure the service server 30 as a cloud service having a hardware configuration that provides resources based on authorization results in addition to the device configuration related to providing authorization services.
[0046] [1.2.3 External terminal device 50] The external terminal device 50 may be, for example, an information processing device with a known configuration, such as a PC, smartphone, tablet, or mobile phone. The configuration of the external terminal device 50 is not particularly limited as long as it has a browser program that generates a Web-User Interface (UI) by rendering screen information acquired via a server function provided by the multifunction peripheral 10. In the device flow authorization method, when user code information or the like is provided from the multifunction peripheral 10, the external terminal device 50 can access an authorization page via a hyperlink on the browser. When the user code information provided from the multifunction peripheral 10 is provided as coded information, the external terminal device 50 may be provided with a decoding unit that acquires the coded information from an imaging unit such as a camera (not shown) and decodes the acquired coded information. Here, the encoded information may be a one-dimensional code such as a barcode (for example, EAN code, JAN code, Codbar, CODE128, etc.), a two-dimensional code (a stacked two-dimensional code (for example, PDF417, CODE49, etc.)), or a matrix two-dimensional code (for example, a quick response code (QR code (registered trademark)), DataMatrix, VeriCode, Aztec, etc.).
[0047] [1.3 Processing flow] Next, the flow of processing according to the first embodiment will be described. Fig. 4 is a flowchart illustrating processing related to acceptance of an authorization method according to the first embodiment. Note that the processing described in Fig. 4 is processing executed by the control unit 11 by reading out the control program 211, the authorization program 213 (authorization method determination program 2131, authorization information acquisition restriction program 2133, notification output program 2135), the browser program 215, the server program 217, etc.
[0048] The control unit 11 accepts the selection of the authorization method depending on whether or not an input is made via either the browser screen of its own device or the service setting screen displayed on the browser screen of the external terminal device 50 (step S10).
[0049] The control unit 11 determines whether the accepted authorization method is the device flow method (step S13). Note that the control unit 11 can determine that the authorization flow method has been selected when the selection of a provider has been accepted via the browser screen of its own device. On the other hand, the control unit 11 can determine that the device flow method has been selected when the selection of a provider has been accepted via the browser screen of the external terminal device 50.
[0050] If the control unit 11 determines that the accepted authorization method is the DeviceFlow method, it determines whether the provider selected as the authorization server supports the DeviceFlow method (step S13; Yes → step S15). In this case, the control unit 11 can determine whether the provider selected by the user supports the DeviceFlow method by referring to the setting items of the provided services (service settings) in the setting information table illustrated in FIG.
[0051] On the other hand, if it is determined that the accepted authorization method is not the device flow method, the control unit 11 shifts the process to step S17 (step S13; No→step S17).
[0052] If the control unit 11 determines that the provider selected by the user supports the DeviceFlow method, it accepts the authorization information acquisition request (step S15; Yes→step S17).
[0053] When the request to obtain authorization information is received, the control unit 11 refers to the connection setting item in the setting information table of Figure 3, sends an authorization request to the provider (service server 30) selected in step S10, and terminates the processing (step S17 → step S19).
[0054] On the other hand, if it is determined that the provider selected by the user does not support the device flow method, the authorization information acquisition request is restricted (step S15; No→step S21).
[0055] Next, the control unit 11 notifies the user via a browser screen or the like of the external terminal device 50 of a message urging the user to select an authorization method other than the device flow method (authorization flow method) as the authorization method, and terminates the processing (step S23).
[0056] [1.4 Example of operation] Prior to describing an example of operation according to the first embodiment, an authorization flow method and a device flow method as authorization methods according to the present disclosure will be described with reference to FIG.
[0057] 5 is a diagram illustrating the exchange of commands and the like between the multifunction peripheral 10 and the service servers 30 (30a, 30b, ...) serving as authorization servers in the authorization flow method (left part of the figure) or the device flow method (right part of the figure). In the following description, the service servers 30 (30a, 30b, ...) that execute the authorization process will be described as the authorization servers 30.
[0058] First, the authorization flow method will be described. In the authorization flow, authorization (authentication) processing is performed between the multifunction peripheral 10 (a browser screen displayed on an operation panel, which is an example of the display unit 13) and the authorization server 30.
[0059] When the authorization process starts, the control unit 11 sends an authorization request to an authorization endpoint (not shown) of the authorization server 30 (1).
[0060] The authorization endpoint of the authorization server 30 returns an authorization screen as an authorization response to the redirect URL (see FIG. 3) of the multifunction peripheral 10. Upon receiving the authorization screen, the multifunction peripheral 10 displays the authorization screen on the browser screen of the operation panel (2).
[0061] The user of the multifunction device 10 inputs authentication information such as his / her login ID and password for the authorization server 30 via the authorization screen displayed on the browser screen, and approves the authorization request of the multifunction device 10 (3).
[0062] When the authorization request is approved, the authorization decision endpoint (not shown) of the authorization server 30 issues an authorization code (4).
[0063] The multifunction device 10 presents the issued authorization code to a token endpoint (not shown) of the authorization server 30 and requests an access token (5).
[0064] The token endpoint of the authorization server 30 checks the validity of the presented authorization code and issues an access token to the multifunction device 10 as a token response (6).
[0065] Next, the device flow method will be described. In the device flow method, authorization (authentication) processing is performed between the external terminal device 50 (Web-UI, not shown) and the authorization server 30.
[0066] When the authorization process is executed by the external terminal device 50, the control unit 11 of the multifunction peripheral 10 sends an authorization request to a device authorization endpoint (not shown) of the authorization server 30 (1).
[0067] The device authorization endpoint of the authorization server 30 returns a response including a device code, a user code, an end-user verification URL, etc. (not shown) to the MFP 10 as an authorization response (2).
[0068] Upon receiving the authorization response, the multifunction device 10 displays the user code and end-user verification URL included in the authorization response to the external terminal device 50 (3). At this time, if the displayed user code and end-user verification URL are, for example, a QR code (registered trademark), the external terminal device 50 decodes the QR code to decode the user code and end-user verification URL.
[0069] After acquiring the user code and the end-user verification URL, the external terminal device 50 accesses the end-user verification endpoint specified by the end-user verification URL via a browser and enters the acquired user code in addition to authentication information such as its own login ID and password (4)'.
[0070] The authorization server 30 verifies the input authentication information and user code. If the authentication information and user code are successfully verified, the authorization server 30 returns an authorization screen to the external terminal device 50 to confirm whether or not to approve the authorization request from the multifunction peripheral 10.
[0071] At this time, after receiving the authorization response, the multifunction device 10 repeats the access token acquisition request by polling or the like until a final result is obtained (4).
[0072] When the authorization request is approved via the authorization screen displayed on the Web-UI of the external terminal device 50, the token endpoint of the authorization server 30 returns an access token to the multifunction device 10 as a token response (5).
[0073] Next, a specific example of operation according to the first embodiment will be described. Fig. 6(a) is a diagram illustrating an example of the configuration of a service setting screen W10 that is displayed on the operation panel (browser screen) of the multifunction peripheral 10 and corresponds to the authorization flow method as the authorization method. Fig. 6(b) is a diagram illustrating an example of the configuration of a service setting screen W20 that is displayed on the Web-UI of the external terminal device 50 and corresponds to the device flow method as the authorization method. Note that the service setting screen W10 shown in Fig. 6(a) and the service setting screen W20 shown in Fig. 6(b) can have the same configuration, and therefore will be described using the same reference numerals.
[0074] The service setting screens W10 and W20 each include a provider setting area R10. The provider setting area R10 includes an authentication method selection pull-down menu P10, a provider selection pull-down menu P12, an account name input box Bx10, and a token acquisition button B10 as a request (means) for obtaining authorization information.
[0075] The authentication method selection pull-down menu P10 is a pull-down menu that accepts the selection of a protocol related to authorization (authentication) processing. FIG. 6 shows an example in which OAuth2.0 is selected as the protocol. The provider selection pull-down menu P12 is a pull-down menu that accepts the selection of a service server 30 (30a, 30b, ...) as a provider (authorization server). FIG. 6 shows an example in which "provider aaa" is selected as the provider (see FIG. 3). The account name input box Bx10 is an input box that accepts the input of an account name for the provider ("provider aaa") selected in the provider selection pull-down menu P12.
[0076] The token acquisition button B10 is a selection button that accepts an instruction to acquire an access token as authorization information. When the token acquisition button B10 is selected, the control unit 11 starts authorization processing for the provider (“provider aaa”) selected in the provider selection pull-down menu P12.
[0077] 6(b) is a setting screen that supports the device flow method as the authorization method. The selected "provider aaa" is a provider that supports the device flow method (see FIG. 3), so there is no notification to prompt the user to select another authorization method, no restriction on the display of the token acquisition button B10, and no change in the display mode of the token acquisition button B10.
[0078] Figures 7(a) and 7(b) are examples of the case where "Provider bbb," which does not support the device flow method as the authorization method, is selected on the service setting screens W10 and W20 illustrated in Figures 6(a) and 6(b).
[0079] The service setting screen W10 displayed on the operation panel (browser screen) of the multifunction device 10 shown in Figure 7(a) uses the authorization flow method as the authorization method, so even if "Provider bbb" is selected as the provider, there is no restriction on the display of the token acquisition button B10 or any change in the display mode.
[0080] On the other hand, the service setting screen W20 displayed on the Web-UI of the external terminal device 50 illustrated in Figure 7(b) uses the device flow method as the authorization method, so when "Provider bbb" is selected as the provider, a notification is displayed urging the user to select another authorization method, the display of the token acquisition button B10 is restricted, and the display mode of the token acquisition button B10 is changed.
[0081] 7(b) shows an example in which the display of the token acquisition button B10 is restricted by superimposing a message M10 that prompts the user to select another authorization method on the token acquisition button B10. Note that message M10 is an example of a message screen that prompts the user to select another authorization method and contains the following notification: "To enable OAuth authentication, you must acquire a token. The selected provider cannot acquire a token from the device web page, so please press the [Acquire] button with the same settings on the device's operation panel to acquire a token."
[0082] As described above, according to the first embodiment, when a user selects authorization processing based on the device flow method as one authorization method using connection information, the authorization server determines whether or not the device flow method is supported. If the authorization server determines that the device flow method is not supported, the authorization server restricts the execution of authorization processing using the device flow method and outputs a notification urging the user to select an authorization flow method that is an authorization method other than the device flow method. This makes it possible to provide an image processing device or the like that can reduce the risk that the authorization processing will be hindered due to the authorization method being applied.
[0083] [2 Second Embodiment] In the second embodiment, either the authorization flow method or the device flow method is set as the authorization method for the authorization server based on the capabilities or device settings of the multifunction device 10, such as when there are restrictions on the browser function, such as when the browser screen displayed on the operation panel of the multifunction device 10 cannot be used, or when authorization processing using the authorization flow in the multifunction device 10 is not permitted.
[0084] The functional configurations of the multifunction peripheral 10, service server 30 (30a, 30b, . . . ), and external terminal device 50 according to the second embodiment can be the same as those of the first embodiment, and therefore will not be described here.
[0085] [2.1 Processing flow] The processing flow according to the second embodiment is obtained by replacing the flowchart according to Fig. 4 of the first embodiment with the flowchart in Fig. 8. Therefore, the same processes as those explained in Fig. 4 are assigned the same step numbers and their explanations will be omitted.
[0086] The control unit 11 determines whether the accepted authorization method is an authorization flow method (step S30). If the control unit 11 determines that the accepted authentication method is an authorization flow, it determines whether the authorization flow is enabled (step S30; Yes → step S32). If the control unit 11 determines that the accepted authentication method is not an authorization flow, it proceeds to step S15 in Fig. 4 (step S30; No → "Go to step S15 in Fig. 4").
[0087] If the control unit 11 determines that the authorization flow method is enabled as the authorization method, it accepts an authorization information acquisition request (step S32; Yes → step S17). Upon accepting the authorization information acquisition request, the control unit 11 transmits an authorization request to the provider (service server 30) selected in step S10, and ends the process (step S17 → step S19).
[0088] On the other hand, if the control unit 11 determines that the authorization flow method is not a valid setting because the browser function is restricted or the multifunction device 10 is set to not allow authorization processing using the authorization flow, the control unit 11 restricts the authorization information acquisition request (step S32; No → step S21).
[0089] Next, the control unit 11 notifies the user via the operation panel (browser screen, etc.) of the multifunction device 10 of a message urging the user to select an authorization method other than the authorization flow method (device flow method) as the authorization method, and terminates the processing (step S23).
[0090] [2.2 Example of operation] Next, an example of operation according to the second embodiment will be described. Fig. 9(a) is a diagram illustrating an example of the configuration of the service setting screen W10 when it is determined that the authorization flow method is enabled as the authorization method in step S32 of Fig. 8. Note that the service setting screen W10 illustrated in Fig. 9(a) has the same configuration as the service setting screen W10 described in Fig. 7(a), and therefore a description thereof will be omitted here.
[0091] On the other hand, the service setting screen W10′ illustrated in FIG. 9(b) is a diagram illustrating an example of the configuration of the service setting screen W10′ when it is determined in step S32 of FIG. 8 that the authorization flow method is not a valid setting as the authorization method.
[0092] In the service setting screen W10' illustrated in Figure 9(b), the authorization flow method is not enabled as an authorization method, so when "Provider aaa" is selected as the provider, a notification is displayed urging the user to select another authorization method, the display of the token acquisition button B10 is restricted, and the display mode of the token acquisition button B10 is changed.
[0093] 9(b) is an example in which a message M12 prompting the user to select another authorization method is superimposed on the token acquisition button B10, thereby restricting the display of the token acquisition button B10. The message M12 is an example of a message screen that prompts the user to select another authorization method and contains the message "To enable OAuth authentication, you must obtain a token. Please obtain a token from the device web page."
[0094] As described above, according to the second embodiment, when the authorization flow method is not enabled as the authorization method, a notification is output prompting the user to select the device flow method as an authorization method other than the authorization flow method, thereby making it possible to provide an image processing device or the like that can reduce the risk that the authorization process will not be realized due to the authorization method being applied.
[0095] [3 Third embodiment] The third embodiment is a form in which the authorization method can be selected from the authorization flow method and the device flow method via an operation panel (browser screen) provided in the multifunction peripheral 10.
[0096] The functional configuration and processing flow of the multifunction device 10, service server 30 (30a, 30b, etc.), and external terminal device 50 in the third embodiment can be the same as those in the first or second embodiment, so explanations will be omitted here.
[0097] [3.1 Example of operation] 10 is a diagram illustrating an example of the configuration of a service setting screen W30 according to the third embodiment. Note that the same components as those in the service setting screen W10 described in FIG. 6 and other figures are denoted by the same reference numerals, and their description will be omitted.
[0098] The service setting screen W30 includes the same configuration as the service setting screen W10, as well as an authorization method selection pull-down menu P14 and a setting button B12.
[0099] The authorization method selection pull-down menu P14 is a pull-down menu that accepts the selection of an authorization method. Fig. 10 shows an example in which the "Device Flow" method is selected as the authorization method. The setting button B12 is a selection button that accepts an instruction to confirm the selection (input) operation in the provider setting area R10.
[0100] 11 shows an example of the configuration of an authorization information display screen W40 that is displayed on an operation panel (browser screen) of the multifunction peripheral 10 when the device flow method is selected as the authorization method via the operation panel. The authorization information display screen W40 includes an authorization information display area R12.
[0101] The user can use an information processing device such as a smartphone or tablet to access the end-user verification endpoint specified by the end-user verification URL displayed in the authorization information display area R12, and enter the acquired user code in addition to authentication information such as the user's login ID and password. The user code and end-user verification URL may also be acquired by reading a QR code (registered trademark) displayed in the authorization information display area R12.
[0102] As described above, according to the third embodiment, in addition to the effects of the first and second embodiments, it is possible to select either the authorization flow method or the device flow method as the authorization method via the operation panel (browser screen) provided on the multifunction device 10, thereby making it possible to provide an image processing device etc. that is easier to use.
[0103] The present disclosure is not limited to the above-described embodiments, and various modifications are possible. In other words, embodiments obtained by combining technical means that are appropriately modified within the scope of the gist of the present disclosure are also included in the technical scope of the present disclosure.
[0104] Furthermore, although the above-described embodiments are described separately for the sake of convenience, they may of course be combined and executed within the scope of technical feasibility.
[0105] In addition, the programs that run on each device in the embodiments are programs that control the CPU, etc. (programs that make a computer function) so as to realize the functions of the above-described embodiments. Information handled by these devices is temporarily stored in a temporary storage device (e.g., RAM) during processing, and then stored in various storage devices such as ROMs (Read Only Memories) and HDDs, and is read, modified, and written by the CPU as needed.
[0106] Here, the computer-readable non-transitory recording medium on which the program is recorded in the information processing device may be any of semiconductor media (e.g., ROM, non-volatile memory card, etc.), optical recording media / magneto-optical recording media (e.g., DVD (Digital Versatile Disc), MO (Magneto Optical Disc), MD (Mini Disc), CD (Compact Disc), BD (Blu-ray (registered trademark) Disc, etc.)), magnetic recording media (e.g., magnetic tape, flexible disk, etc.). In this case, the program recorded on the recording medium is read by the computer of the information processing device and executed by the computer, thereby realizing not only the functions of the above-mentioned embodiments, but also the functions of the present disclosure, which are realized by processing in cooperation with an operating system or other application programs, etc., based on instructions from the program.
[0107] Furthermore, when distributing the program on the market, the program can be stored in a portable recording medium and distributed, or transferred to a server computer connected via a network such as the Internet. In this case, the storage device of the server computer is also included in the present disclosure.
[0108] Additionally, each functional block or feature of the device used in the above-described embodiments may be implemented or performed by an electrical circuit, such as an integrated circuit or multiple integrated circuits. The electrical circuit designed to realize the functions described herein may include a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic device, discrete gates or Tronistor logic, discrete hardware components, or a combination thereof. The general-purpose processor may be a microprocessor, a conventional processor, a controller, a microcontroller, or a state machine. The electrical circuit may be composed of digital circuits or analog circuits. Furthermore, as advances in semiconductor technology emerge, one or more aspects of the present disclosure may utilize new integrated circuits based on that technology. [Explanation of symbols]
[0109] 11 Control section 13 Display section 15 Operation input section 17 Communications Department 19 Image processing section 191 Image forming unit 193 Image Input Unit 21 Memory section 211 Control Program 213 Accredited Program 2131 Authorization Method Judgment Program 2133 Authorization Information Acquisition Restriction Program 2135 Notification Output Program 215 Browser Program 217 Server Program 219 Setting information storage area
Claims
1. An image forming apparatus that executes authorization processing via a setting screen displayed on an external device based on screen information provided to the external device, the image forming apparatus, receiving from the external device and executing an instruction to transmit connection information for connecting to an authorization server configured with one or more servers selected on the setting screen to the authorization server based on the HTTPS protocol; displaying the user code and URL received from the authorization server on the external device; user authentication is performed between the authorization server indicated by the URL and the external device based on the user code, and if the user authentication is successful, information indicating that the user authentication has been successful is received from the authorization server selected on the setting screen; The image forming apparatus is characterized in that information indicating that the user authentication has been successful is displayed on the external device.
2. The image forming apparatus comprises:
2. The image forming apparatus according to claim 1, wherein the external device displays a token acquisition status before the user authentication is performed.
3. The image forming apparatus comprises:
2. The image forming apparatus according to claim 1, wherein the authentication method selected on the setting screen and information related to the authorization server are displayed on the same screen of the external device.
4. The image forming device described in Claim 1, characterized in that the user authentication uses the user code entered on the setting screen and the user's authentication information of the external device for the authorization server indicated by the URL.
Citation Information
Patent Citations
Information processing system, control method, and service providing device
JP2017010266A
Information processing system, control method thereof, and program
JP2019139520A
Information processing device and information processing device control method
JP2021152835A
Authorization server device, processing method of authorization server device, and program
JP2022054025A
Enhanced security for device authorization for browserless or input-constrained devices
US20230291723A1