Image processing system, control method for image processing system, and program
The image processing system enhances security by implementing a two-step authentication process using an information terminal and authentication server to prevent unauthorized access and ensure secure document processing.
Patent Information
- Application Number
- JP2021131091
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-08-11
- Publication Date
- 2026-02-24
- Estimated Expiration
- 2041-08-11
AI Technical Summary
Conventional image processing systems allow unauthorized users with stolen authentication information to access and use the system, posing a security risk.
An image processing system that includes an information terminal to receive user information, perform a first authentication process, and upon successful authentication, transmit a one-time password to an authentication server for a second authentication process, ensuring secure document reading and data generation.
Enhances security by requiring multiple authentication steps, preventing unauthorized access and ensuring secure document processing.
Smart Images

Figure 0007818912000001 
Figure 0007818912000002 
Figure 0007818912000003
Abstract
Description
[Technical Field]
[0001] The present invention provides picture Image Processing System , image processing system control method, and program - Patents.com to Seki This is what we do. [Background technology]
[0002] A technology has been disclosed in which authentication information corresponding to the user to be used is obtained from a user management server, login processing is performed, and then a job is executed on an image forming device based on a job ticket obtained from the server (see Patent Document 1). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2004-185629 Summary of the Invention [Problem to be solved by the invention]
[0004] In conventional technology, any user who knows the authentication information can use the image processing device, so if the authentication information is stolen, there is a risk that a malicious user may be able to use the service via the image processing device.
[0005] Book technology This was done in consideration of the above issues. technology The purpose of the information terminal is to receive user information from a user, transmit the user information to an authentication server, and The first authentication process is performed based on the user information, and as a result of the first authentication process, the authentication server Accept the code sent from the user, original transmitting information used to cause the image processing device to execute a process of reading the manuscript without waiting for reception of the code from the user; a second authentication process based on the code is executed by the authentication server, and authentication information transmitted from the authentication server as a result of the second authentication process is transmitted to the image processing device; The image processing device reads the document in response to receiving the information, and generates image data by reading the document. and , the information terminal Credentials sent from The purpose of this invention is to provide a mechanism for transmitting the above to an external device. [Means for solving the problem]
[0006] An image processing system comprising: an image processing device; and an information terminal, wherein the information terminal receives user information from a user and transmits the user information to an authentication server; A first authentication process based on the user information is executed by Accepting the transmitted code from the user; original transmitting information used to cause the image processing device to execute a process of reading a manuscript without waiting for reception of the code from the user; transmitting the code to the authentication server, the authentication server executing a second authentication process based on the code, and transmitting authentication information transmitted from the authentication server as a result of the second authentication process to the image processing device; In response to receiving the information, the image processing device The aforementioned Scanning an original and generating image data by scanning the original and , the information terminal The authentication information sent from of 、 The feature is that the information is transmitted to an external device. [Effects of the Invention]
[0007] Book technology According to the method, an information terminal receives user information from a user, transmits the user information to an authentication server, and The first authentication process is performed based on the user information, and as a result of the first authentication process, the authentication server Accept the code sent from the user, original transmitting information used to cause the image processing device to execute a process of reading the manuscript without waiting for reception of the code from the user; a second authentication process based on the code is executed by the authentication server, and authentication information transmitted from the authentication server as a result of the second authentication process is transmitted to the image processing device; The image processing device reads the document in response to receiving the information, and generates image data by reading the document. and , the information terminal Credentials sent from can be transmitted to an external device. [Brief explanation of the drawings]
[0008] [Figure 1] System configuration diagram of this embodiment [Figure 2] FIG. 1 is a block diagram showing the configuration of an image forming apparatus according to an embodiment of the present invention. [Figure 3]FIG. 1 is a block diagram showing the configuration of an information terminal according to an embodiment of the present invention. [Figure 4] 1 is a block diagram showing the configuration of a cloud server according to an embodiment of the present invention; [Figure 5] FIG. 1 is a block diagram showing the configuration of an authentication server according to an embodiment of the present invention. [Figure 6] FIG. 10 is a diagram showing an example of a screen in this embodiment. [Figure 7] 1 is a flowchart showing a user information registration process according to an embodiment of the present invention; [Figure 8] 1 is a flowchart showing a service URL registration process according to an embodiment of the present invention. [Figure 9] 1 is a flowchart showing two-step authentication processing in this embodiment. [Figure 10] FIG. 10 is a diagram showing a screen flow of a scan application in the present embodiment. [Figure 11] FIG. 10 is a diagram showing a screen flow of a print application in this embodiment. [Figure 12] FIG. 1 is a sequence diagram showing a first scan control in this embodiment. [Figure 13] FIG. 10 is a diagram showing an example of a first scan job ticket in this embodiment. [Figure 14] 1 is a flowchart illustrating processing of a scan job in this embodiment. [Figure 15] 1 is a flowchart showing a scan job execution process of an image forming apparatus according to an embodiment of the present invention; [Figure 16] Print control sequence diagram in this embodiment [Figure 17] FIG. 1 shows a print job ticket according to this embodiment. [Figure 18] 1 is a flowchart relating to print job processing in this embodiment. [Figure 19] 1 is a flowchart showing a print job execution process according to the present embodiment. [Figure 20] FIG. 10 is a sequence diagram showing a second scan control in this embodiment. [Figure 21] FIG. 10 is a sequence diagram showing a third scan control in the present embodiment. [Figure 22]FIG. 10 is a diagram showing an example of a second scan job ticket in this embodiment. [Figure 23] FIG. 10 is a diagram showing an example of an authentication ticket in this embodiment. [Figure 24] 10 is a flowchart illustrating an example of a scan job execution process according to the present embodiment. [Figure 25] FIG. 10 is a sequence diagram showing a fourth scan control in the present embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0009] Hereinafter, embodiments of the present invention will be described with reference to the accompanying drawings. Note that the image forming apparatus in this embodiment is an example of an image processing apparatus. The following embodiments do not limit the scope of the invention as claimed, and not all of the combinations of features described in the embodiments are necessarily essential to the solution of the invention.
[0010] Example 1 In this embodiment, the IP address of the image forming apparatus 101 is "192.168.1.101." The IP address of the information terminal 102 is "192.168.1.100." These IP addresses are merely examples, and other IP addresses may be used. Furthermore, a URL that the image forming apparatus 101 and the information terminal 102 access via the network 105 to use a service of the cloud server 103, such as online storage, is referred to as a service URL. The service URL and the authentication information corresponding to the service URL, that is, a "user name" and a "password," are assumed to be registered in advance on a service URL registration screen (not shown) and stored in the storage 305 of the information terminal 102.
[0011] <Overall structure> Fig. 1 is a diagram showing an example of a system configuration of this embodiment. As shown in Fig. 1, the image processing system of this embodiment is composed of, for example, an image forming apparatus 101, an information terminal 102, a cloud server 103, an authentication server 104, a network 105, and a public line 106.
[0012] The image forming apparatus 101, the information terminal 102, the cloud server 103, and the authentication server 104 can communicate with each other via a network 105. The information terminal 102 and the authentication server 104 can also communicate with each other via a public line 106. Note that instead of one image forming apparatus 101, multiple apparatuses may be connected. Multiple information terminals 102 may also be connected.
[0013] The image forming apparatus 101 is a multifunction device having multiple functions such as copying, scanning, printing, and faxing.
[0014] The information terminal 102 is, for example, a smartphone used by a user. The information terminal 102 may be a mobile phone or a tablet other than a smartphone. The information terminal 102 generates a scan job for scanning a paper document using the image forming apparatus 101, and generates a print job for printing an image file stored in the cloud server 103 using the image forming apparatus 101. The image forming apparatus 101 also includes a means for acquiring a one-time password from the authentication server 104 via the public line 106.
[0015] Cloud server 103 is configured by one or more cloud servers, and provides a service for managing electronic files including image data, and manages user information for accessing the electronic files. Cloud server 103 also includes an authentication means for enabling information terminal 102 or image forming apparatus 101, which is the source of the notification, to access the electronic files based on authentication information notified via network 105.
[0016] The authentication server 104 has a function of decrypting authentication information received from the cloud server 103. The authentication server 104 also has a means for issuing a one-time password, which is a password that can be used to authenticate a user only for a predetermined period of time, and notifying the one-time password to a device registered in association with the user via a short message service (SMS) over the public line 106. Note that the means for notifying the one-time password may be a means for sending an email containing the one-time password over the network 105. However, the present invention is not limited to this, and may also be a means for sending the one-time password over the network 105 to an application installed in the information terminal 102 for obtaining authentication information.
[0017] <Hardware configuration of image forming device> FIG. 2 is a block diagram showing a schematic configuration of an image forming apparatus 101 according to an embodiment of the present invention.
[0018] As shown in FIG. 2, the image forming apparatus 101 includes a CPU 202, a RAM 203, a ROM 204, a storage 205, a network I / F 206, an operation I / F 207, a print controller 209, and a scan controller 211, all connected to a system bus 201.
[0019] A CPU (Central Processing Unit) 202 controls the overall operation of the image forming apparatus 101. The CPU 202 reads out a control program stored in a ROM 204 or a storage 205, and performs various controls such as reading control and printing control.
[0020] The RAM 203 is the main storage memory of the CPU 202 and is used as a temporary storage area for loading various control programs stored in the ROM 204 or the storage 205 .
[0021] The ROM 204 stores programs that can be executed by the CPU 202 .
[0022] The storage 205 is, for example, a hard disk drive (HDD) that stores image data, various programs, and various setting information. The storage 205 may be a solid state drive (SSD) or may be replaced with another storage device having the same functions as the HDD.
[0023] In the image forming apparatus 101 of this embodiment, one CPU 202 executes each process shown in the flowcharts described below, but other configurations are also possible. For example, multiple CPUs, RAMs, ROMs, and storages can work together to execute each process shown in the flowcharts described below. Also, some of the processes may be executed using hardware circuits such as an ASIC (Application Specific Integrated Circuit) or an FPGA (Field-Programmable Gate Array).
[0024] The network I / F 206 is an interface that enables the image forming apparatus 101 to communicate with external devices via the network 105. The image forming apparatus 101 transmits image data generated by scanning an original with the scanner 212 via the network I / F 206 to the cloud server 103 or a server somewhere on the network 105. The image forming apparatus 101 also receives data managed by the cloud server 103 or a server somewhere on the network 105 via the network I / F 206, and prints the data using the print engine 210.
[0025] The operation panel 208 has, for example, a touch panel or hard keys. The operation panel 208 displays a screen controlled by the operation I / F 207. When a user operates the operation panel 208, the image forming apparatus 101 acquires an event corresponding to the user operation via the operation I / F 207.
[0026] The print controller 209 is connected to the print engine 210. Image data to be printed is transferred to the print engine 210 via the print controller 209. The print engine 210 receives control commands and the image data to be printed, and forms an image on a sheet based on this image data. The printing method of the print engine 210 may be an electrophotographic method or an inkjet method. In the case of the electrophotographic method, an electrostatic latent image is formed on a photosensitive member, and then developed with toner, and the toner image is transferred to a sheet, and the transferred toner image is fixed to form an image. On the other hand, in the case of the inkjet method, an image is formed on a sheet by ejecting ink.
[0027] The scan controller 211 is connected to a scanner 212. The scanner 212 reads an image of an original document and generates image data. The image data generated by the scanner 212 is stored in a storage 205. The image forming apparatus 101 can form an image on a sheet using a print engine 210 based on the image data generated by the scanner 212. The scanner 212 has a document feeder (not shown) and can read documents placed on the document feeder one by one while transporting the documents.
[0028] <Hardware configuration of information terminal> FIG. 3 is a diagram showing an example of the hardware configuration of the information terminal 102 according to the embodiment of the present invention.
[0029] As shown in FIG. 3, the information terminal 102 includes a CPU 302 , a RAM 303 , a ROM 304 , a storage 305 , a network I / F 306 , an operation unit 307 , a display unit 308 , and a public line I / F 309 , all connected to a system bus 301 .
[0030] The CPU 302 is a central processing unit that controls the overall operation of the information terminal 102. The RAM 303 is a volatile memory that functions as a work area for the CPU 302. The ROM 304 is a non-volatile memory that stores a startup program and various programs. The storage 305 is a storage device (for example, a hard disk drive (HDD)) with a larger capacity than the RAM 303. The storage 305 may be a solid state drive (SSD) or may be replaced with another storage device that has the same functions as an HDD.
[0031] Upon startup, such as when the power is turned on, the CPU 302 executes a startup program stored in the ROM 304. This startup program reads the control program stored in the storage 305 and loads it on the RAM 303. After executing the startup program, the CPU 302 subsequently executes the control program loaded on the RAM 303 and performs control. The CPU 302 also stores data used when executing the control program in the RAM 303 and reads and writes it. Various settings required when executing the control program can also be stored in the storage 305, and are read and written by the CPU 302. The information terminal 102 communicates with other devices on the network 104 via the network I / F 306. The information terminal 102 can also accept operations / inputs / instructions performed by a user via the operation unit 307. The information terminal 102 can also display the contents controlled by the CPU 302 on the display unit 308. The information terminal 102 also communicates with other devices on the public line 106 via the public line I / F 309.
[0032] <Cloud server hardware configuration> FIG. 4 is a diagram illustrating an example of the hardware configuration of the cloud server 103 according to an embodiment of the present invention.
[0033] As shown in FIG. 4, the cloud server 103 includes a CPU 402 , a RAM 403 , a ROM 404 , a storage 405 , and a network I / F 406 connected to a system bus 401 .
[0034] The CPU 402 is a central processing unit that controls the overall operation of the cloud server 103. The RAM 403 is a volatile memory that functions as a work area for the CPU 302. The ROM 404 is a non-volatile memory that stores a startup program and various other programs. The storage 405 is a large-capacity storage device (for example, a hard disk drive (HDD)). The storage 405 may be a solid-state drive (SSD) or may be replaced with another storage device that has the same functions as a hard disk drive.
[0035] The cloud server 103 communicates with other devices on the network 104 via the network I / F 406 .
[0036] <Authentication server hardware configuration> FIG. 5 is a diagram showing an example of the hardware configuration of the authentication server 104 according to an embodiment of the present invention.
[0037] As shown in FIG. 5, the authentication server 104 includes a CPU 502 , a RAM 503 , a ROM 504 , a storage 505 , a network I / F 506 , and a public line I / F 507 connected to a system bus 501 .
[0038] The CPU 502 is a central processing unit that controls the overall operation of the authentication server 104. The RAM 503 is a volatile memory that functions as a work area for the CPU 502. The ROM 504 is a non-volatile memory that stores a startup program and various other programs. The storage 505 is a storage device (for example, a hard disk drive: HDD) with a larger capacity than the RAM 503. The storage 505 may be a solid state drive (SSD) or may be replaced with another storage device that has the same functions as a hard disk drive.
[0039] The authentication server 104 communicates with other devices on the network 105 via a network I / F 406. The CPU 502 communicates with other devices on the public line 106 via a public line I / F 507.
[0040] <User information registration process> Next, the user information registration process performed using the information terminal 102 will be described.
[0041] FIG. 7 is a flowchart of a user information registration process executed by the authentication server 104 and the information terminal 102 according to an embodiment of the present invention. Each process in the flowcharts of FIGS. 7A and 7B is performed by the CPU 502 of the authentication server 104 reading a program stored in the ROM 504 into the RAM 503 and executing it. Each process in the flowchart of FIG. 7C is performed by the CPU 302 of the information terminal 102 reading a program stored in the ROM 304 into the RAM 303 and executing it. Based on a user's operation of the web browser, the information terminal 102 sends a user registration screen acquisition request to the cloud server 103 using an HTTP POST request. Having received the POST request, the cloud server 103 sends HTTP response data to the information terminal 102, together with HTML data for displaying the user registration screen. The CPU 302 of the information terminal 102 displays the user registration screen (FIG. 6A) on the display unit 308 based on the received HTML data. This user registration screen is displayed on the web browser. The user enters information into an email address text box 601, a phone number text box 602, a user ID text box 603, and a password text box 604. When the user then presses a registration button 605, the CPU 302 of the information terminal 102 executes a user information transmission process (FIG. 7(C)). Here, the user enters the phone number of a device that the user owns into the phone number text box 602. In this embodiment, the information terminal 102 is used as an example of a device that the user owns, but the device that the user owns may be a device different from the information terminal 102.
[0042] In step 715 (hereinafter referred to as S715), CPU 302 of information terminal 102 saves in RAM 303 the email address string that was entered in email address text box 601 on the user registration screen (FIG. 6(A)). CPU 302 also saves in RAM 303 the telephone number string that was entered in telephone number text box 602. CPU 302 also saves in RAM 303 the user ID string that was entered in user ID text box 603. CPU 302 also saves in RAM 303 the password string that was entered in password text box 604. CPU 302 saves this information in RAM 303 as registration information.
[0043] In step S716, the CPU 302 of the information terminal 102 sends a registration request to the cloud server 103, to which the registration information in the RAM 303 has been added, by using an HTTP POST request.
[0044] In step S717, the CPU 302 of the information terminal 102 receives the HTTP response data as a response to the registration request, and stores the received data in the RAM 303 as a response to the registration request.
[0045] In step S718, the CPU 302 of the information terminal 102 causes the display unit 308 to display a transmission result screen based on the HTML data attached to the registration request response.
[0046] When the cloud server 103 redirects the HTTP request for registration with the registration information received in S715 to the authentication server 104, the CPU 502 of the authentication server 104 executes the user information provisional registration process (FIG. 7A).
[0047] In step S701, the CPU 502 of the authentication server 104 acquires registration information from the HTTP request for the registration request and stores it in the RAM 503.
[0048] In step S702, the CPU 502 of the authentication server 104 determines that a password error has occurred if the password character string in the registration information in the RAM 503 violates the password rules. Examples of password rules include "contains all alphanumeric characters, uppercase letters, lowercase letters, and special symbols" and "must be at least 10 characters long."
[0049] If it is not determined in S702 that there is a password error, in S703 the CPU 502 of the authentication server 104 stores the registration information and expiration date in the RAM 503 in a temporary registration table on the storage 505 of the authentication server 104. An example of the expiration date is 10 minutes after the time S703 is executed.
[0050] In S704, the CPU 502 of the authentication server 104 generates a token string, which is a character string obtained by encrypting the user ID included in the registration information in the RAM 503. Then, the CPU 502 of the authentication server 104 sends an email to the email address in the registration information, with the main registration URL to which the token string has been added written in the body of the email.
[0051] In step S705, the CPU 502 of the authentication server 104 transmits HTTP response data to the cloud server 103, with a provisional registration completion notice attached, as a response to the registration request.
[0052] If it is determined in S702 that the password is incorrect, in S706 the CPU 502 of the authentication server 104 transmits HTTP response data to the cloud server 103 along with the reason for the violation as a response to the registration request.
[0053] When CPU 402 of cloud server 103 receives the provisional registration completion in S705, it transmits HTTP response data to which HTML data for displaying a provisional registration completion screen (not shown) is added to information terminal 102 as a response to the registration request.
[0054] The user accesses the URL for main registration written in the body of the email received in S704 on the web browser of information terminal 102. When an HTTP request for main registration is sent to cloud server 103, cloud server 103 redirects the HTTP request for main registration to authentication server 104. CPU 502 of authentication server 104 executes main registration processing (FIG. 7(B)).
[0055] In step S707, the CPU 502 of the authentication server 104 stores in the RAM 503 the token character string assigned to the official registration URL.
[0056] In step S708, if the user ID acquired by decrypting the token character string in the RAM 503 is not in the temporary registration table in the storage 505, the CPU 502 of the authentication server 104 determines that a token error has occurred.
[0057] If it is not determined in S708 that there is a token error, in S709 the CPU 502 of the authentication server 104 obtains provisional registration information from the provisional registration table in the storage 505 based on the user ID obtained by decrypting the token string, and stores the information in the RAM 503.
[0058] In S710, the CPU 502 of the authentication server 104 determines that the temporary registration information on the RAM 503 has expired if the expiration date is later than the time of execution of S708. Also, if the temporary registration information associated with the user ID decrypted in S706 cannot be acquired, the authentication server 104 determines that the temporary registration information has expired.
[0059] If it is determined in S710 that the expiration date has not passed, in S711 the CPU 502 of the authentication server 104 stores the permanent registration information consisting of the email address, telephone number, user ID, and password of the provisional registration information on the RAM 503 in the registration information table on the storage 505.
[0060] In step S712, the CPU 502 of the authentication server 104 transmits HTTP response data indicating completion of registration to the cloud server 103 as a response to the main registration request.
[0061] If it is determined in S708 that a token error has occurred, in S713 the CPU 502 of the authentication server 104 transmits HTTP response data with a token error attached to the cloud server 103 as a response to the main registration request.
[0062] If it is determined in S710 that the expiration date has passed, in S714 the CPU 502 of the authentication server 104 transmits HTTP response data to which the expiration date has been added to the cloud server 103 as a response to the official registration request.
[0063] <Service URL registration> FIG. 8 is a diagram showing a flowchart of service URL registration executed by information terminal 102 according to an embodiment of the present invention. Each process in the flowchart in FIG. 8 is performed by CPU 302 of information terminal 102 reading a program stored in ROM 304 into RAM 303 and executing it. The user registers a user ID and password by performing user information registration processing (FIG. 7) in advance for the service they wish to use. Then, the user inputs information into service URL text box 606, user ID text box 607, and password text box 608 on the service URL registration screen (FIG. 6(B)) on the scan application or print application of information terminal 102. When the user then presses register button 609, CPU 302 of information terminal 102 executes service URL provisional registration processing (FIG. 8(A)).
[0064] In S800, the CPU 302 of the information terminal 102 saves the registration information entered in the user ID text box 607 and password text box 608 in the RAM 303. Then, the CPU 302 executes a process of transmitting HTTP request data for a registration information confirmation request, to which the registration information has been added, to the service URL corresponding to the service of the cloud server 103 entered in the service URL text box 606.
[0065] In step S801, the CPU 302 of the information terminal 102 receives the registration information confirmation result from the cloud server 103 as an HTTP response.
[0066] In S802, if the registration information confirmation result received in S801 is "present," the CPU 302 of the information terminal 102 determines that registration information is present.
[0067] If it is determined in S802 that registration information exists, the CPU 302 of the information terminal 102 transmits HTTP request data for a one-time password acquisition request, to which the user ID and password are attached, to the cloud server 103 in S803.
[0068] In S804, the CPU 302 of the information terminal 102 displays a one-time password entry screen (FIG. 6C) on the display unit 308 of the information terminal 102.
[0069] If it is determined in S802 that there is no registered information, in S805 the CPU 302 of the information terminal 102 displays on the display unit 308 a service URL registration screen (not shown) with an error message that specifies the cause of the error.
[0070] After sending the first authentication request in S803, the cloud server 103 redirects the HTTP request data of the authentication request to the authentication server 104. Then, the authentication server 104 executes the first authentication process (FIG. 9(A)) to send a one-time password by SMS to the telephone number of the information terminal 102. The user enters the one-time password written in the SMS received by the information terminal 102 into the one-time password text box 610 on the one-time password input screen (FIG. 6(C)). Then, when the user presses the send button 611, the CPU 302 of the information terminal 102 executes the service URL official registration process (FIG. 8(B)).
[0071] In step S806, the CPU 302 of the information terminal 102 transmits HTTP request data for a second authentication request, to which the one-time password entered in the one-time password text box 610 has been added, to the cloud server 103. The CPU 302 of the information terminal 102 then obtains the second authentication result in the HTTP response.
[0072] In step S807, if the second authentication result acquired in step S806 is successful, the CPU 302 of the information terminal 102 determines that the authentication is successful.
[0073] If it is determined in S807 that the authentication is successful, the CPU 302 of the information terminal 102 saves the registration information on the RAM 303 in the storage 305 of the information terminal 102 in S808.
[0074] In S809, the CPU 302 of the information terminal 102 displays a registration completion screen (not shown) on the display unit 308.
[0075] If it is determined in S807 that the authentication was not successful, in S811 the CPU 302 of the information terminal 102 displays on the display unit 308 a one-time password input screen (not shown) with an error message that specifies the cause of the error.
[0076] <Two-step authentication process> Fig. 9 is a flowchart of two-step authentication processing executed by the CPU 502 of the authentication server 104. Each process in the flowchart of Fig. 9 is performed by the CPU 502 of the authentication server 104 by reading a program stored in the ROM 504 into the RAM 503 and executing it.
[0077] The CPU 502 executes the first authentication process (FIG. 9A) when it receives HTTP request data redirected by the cloud server 103 of the first authentication request sent by the information terminal 102 in the one-time password request (S803) of the service URL registration process (FIG. 8). Similarly, the CPU 502 executes the first authentication process (FIG. 9A) when it similarly receives HTTP request data in the authentication information transmission (S1402) of the scan job flowchart (FIG. 14) on the scan application side. Similarly, the CPU 502 executes the first authentication process (FIG. 9A) when it similarly receives HTTP request data in the authentication information transmission (S1802) of the print job flowchart (FIG. 18) on the print application side.
[0078] In step S901, if the user ID assigned to the first authentication request exists in the registration information table of the storage 505, the CPU 502 of the authentication server 104 determines that the user ID is valid.
[0079] If the user ID is determined to be valid in S901, the CPU 502 of the authentication server 104 determines whether two-step authentication is required in S902. The cloud server 103 can set read permission for reading files stored in the storage 505 and write permission for saving files to the storage 505 for each user from a two-step authentication setting screen (FIG. 6(D)). Whether two-step authentication is required is determined based on the permission granted in the first authentication request and the permission for each user. For a user with two-step authentication settings (FIG. 6(D)), the read permission checkbox 612 is unchecked and the write permission checkbox 613 is checked. Therefore, if write permission is granted in the first authentication request, it is determined that two-step authentication is required, and if read permission is granted in the first authentication request, it is determined that two-step authentication is not required.
[0080] If it is determined in step S902 that two-step authentication is required, then in step S903 the CPU 502 of the authentication server 104 determines that a one-time password has been generated if the user ID assigned to the first authentication request exists in the one-time password management table.
[0081] If it is determined in S903 that the one-time password has already been generated, the CPU 502 of the authentication server 104 deletes the one-time password information corresponding to the user ID attached to the first authentication request from the one-time password management table in S904.
[0082] If it is determined in S903 that a one-time password has not been generated, or after S904 is executed, the CPU 502 of the authentication server 104 generates a one-time password, which is a random four-digit number, in S905. Then, the CPU 502 stores one-time password information, including the user ID assigned to the first authentication request, the generated one-time password, and the one-time password expiration date, in the one-time password management table of the storage 505. An example of the one-time password expiration date is 10 minutes after S905 is executed.
[0083] In S906, the CPU 502 of the authentication server 104 obtains the telephone number associated with the user ID assigned to the first authentication request from the registration information table, and transmits the one-time password generated in S905 by SMS.
[0084] In step S907, the CPU 502 of the authentication server 104 transmits HTTP response data indicating successful transmission to the cloud server 103 as a response to the first authentication request.
[0085] If it is determined in step S902 that two-step authentication is not required, the CPU 502 of the authentication server 104 transmits HTTP response data in step S908. This HTTP response data includes the authentication result "authentication successful" as a response to the first authentication request, and "authentication information" that is information used by the image forming apparatus 101 to access the cloud server 103.
[0086] If it is determined in S901 that the user ID is not valid, in S909 the CPU 502 of the authentication server 104 transmits HTTP response data with an authentication failure attached to it to the cloud server 103 as a response to the first authentication request.
[0087] After transmitting the one-time password in S906, the user inputs the one-time password received via SMS from the operation unit 307 of the information terminal 102. Thereafter, the information terminal 102 transmits HTTP request data of a second authentication request, to which the user ID and one-time password are attached, to the cloud server 103. The second authentication request transmitted by the information terminal 102 in the one-time password transmission step (S1409) of the scan job flowchart (FIG. 14) on the scan application side is redirected by the cloud server 103, and the authentication server 104 receives the HTTP request data. Upon receiving the HTTP request data, the CPU 502 of the authentication server 104 executes second authentication processing (FIG. 9B). Similarly, when the authentication server 104 receives HTTP request data in the one-time password transmission step (S1810) of the print job flowchart (FIG. 18) on the print application side, the CPU 502 of the authentication server 104 executes second authentication processing (FIG. 9B).
[0088] In S910, if the user ID and one-time password attached to the second authentication request do not exist in the one-time password management table, the CPU 502 of the authentication server 104 determines that the passwords do not match.
[0089] If it is determined in S910 that the passwords do not match, the CPU 502 of the authentication server 104 proceeds to S911. In S911, the CPU 502 of the authentication server 104 determines that the expiration date of the one-time password information corresponding to the user ID and one-time password attached to the second authentication request has expired if the expiration date is before the execution time of S910.
[0090] If it is determined in S911 that the expiration date has not expired, the CPU 502 of the authentication server 104 proceeds to S912. In S912, the CPU 502 of the authentication server 104 transmits HTTP response data to the cloud server 103 in response to the second authentication request. This HTTP response data is transmitted together with the authentication result "authentication successful" and "authentication information" that is information for the image forming apparatus 101 to access the cloud server 103.
[0091] In S913, the CPU 502 of the authentication server 104 deletes the one-time password information corresponding to the user ID attached to the second authentication request from the one-time password management table.
[0092] If it is determined in S911 that the one-time password has expired, in S914 the CPU 502 of the authentication server 104 deletes the one-time password information corresponding to the user ID attached to the second authentication request from the one-time password management table.
[0093] If it is determined in S910 that the passwords do not match, or after S914 is executed, HTTP response data with an authentication failure attached thereto is transmitted to the cloud server 103 in response to the second authentication request in S909.
[0094] <Scan app UI flow> FIG. 10 is a diagram showing the screen flow of a scan application, which is an application for executing a scan and is displayed on the information terminal 102 in this embodiment.
[0095] When the user starts the scan application on the information terminal 102, the CPU 302 of the information terminal 102 causes the display unit 308 to display a device selection screen 1000.
[0096] The device selection screen 1000 has a product name specification list box 1001 and a decision button 1002 arranged thereon, and the product name specification list box 1001 is used to specify the image forming device 101 that will perform scanning.
[0097] When the enter button 1002 is pressed, the CPU 302 of the information terminal 102 saves the information of the image forming device 101 specified in the product name specification list box 1001 in the RAM 303, generates a scan setting screen 1003, and displays it on the display unit 308.
[0098] The scan setting screen 1003 includes a color mode specification list box 1004, a resolution specification list box 1005, an input method specification list box 1006, a service URL specification list box 1007, and a scan start button 1008. The color mode specification list box 1004 is used to specify the color mode for scanning. The resolution specification list box 1005 is used to specify the resolution of the image to be scanned. The input method specification list box 1006 is used to specify the image reading method, either "pressure plate" or "ADF." The service URL specification list box 1007 is used to specify the service URL of the registration information stored in the storage 305. An example of a service URL is a cloud storage URL such as Google Drive (registered trademark) "https: / / cloud.Google.com." Another example of a service URL is a cloud storage URL such as OneDrive (registered trademark) "https: / / www.microsoft.com / onedrive."
[0099] When the scan start button 1008 is pressed, the CPU 302 of the information terminal 102 saves the scan settings specified in 1004 to 1007 in the RAM 303. Then, the CPU 302 sends HTTP request data of a first authentication request to the selected service URL, together with the user ID and password of the registration information corresponding to the service URL and a write permission request for requesting writing to the cloud server.
[0100] When HTTP response data indicating authentication failure is received in response to the first authentication request, the CPU 302 of the information terminal 102 displays on the display unit 308 the scan setting screen 1003 on which an error message is displayed based on the received error content.
[0101] When HTTP response data indicating successful transmission is received in response to the HTTP request data of the first authentication request, the CPU 302 of the information terminal 102 causes the display unit 308 to display a one-time password entry screen 1009 .
[0102] The one-time password input screen 1009 has arranged thereon a one-time password input text box 1010, a send button 1011, and a close button 1012. When the user inputs a one-time password in the one-time password input text box and presses the send button 1011, the CPU 302 of the information terminal 102 transmits HTTP request data of a second authentication request to which the input one-time password has been attached.
[0103] When HTTP response data indicating authentication failure is received in response to the second authentication request, the CPU 302 of the information terminal 102 displays on the display unit 308 a one-time password input screen 1009 on which an error message is displayed based on the received error content.
[0104] When HTTP response data indicating successful authentication is received in response to the first authentication request, or when HTTP response data indicating successful authentication is received in response to the second authentication request, the CPU 302 of the information terminal 102 transmits a scan job ticket to the image forming apparatus 101. The CPU 302 also causes the display unit 308 to display a scanning screen 1013. The image forming apparatus 101 receives this scan job ticket and executes a scan job. Specifically, the scan job includes scan settings set on the scan setting screen 1003, and the CPU 202 causes the scanner 212 to scan a document based on these scan settings. Image data generated by scanning the document is stored in the storage 205 and transmitted to the cloud server 103.
[0105] A scan cancel button 1014 is arranged on the scan in progress screen 1013, and when the user presses the scan cancel button 1014, the CPU 302 of the information terminal 102 transmits a job cancel command to the image forming apparatus 101. While the scan in progress screen 1013 is displayed, the CPU 302 of the information terminal 102 acquires the status of the image forming apparatus 101 at 100 msec intervals. If the scan execution result of the acquired status is "success", the CPU 302 of the information terminal 102 displays a transmission success screen 1015 on the display unit 308. On the other hand, if the scan execution result of the acquired status is "failure", the CPU 302 of the information terminal 102 displays an error screen 1016 on the display unit 308.
[0106] A close button 1012 is arranged on the transmission success screen 1015, and when the user presses the close button 1012, the CPU 302 of the information terminal 102 ends the scan application.
[0107] The error screen 1016 has a close button 1012 arranged thereon, and when the user presses the close button 1012, the CPU 302 of the information terminal 102 ends the scan application.
[0108] <Print app UI flow> FIG. 11 is a diagram showing a screen flow of a print application, which is an application for executing printing and is displayed on the information terminal 102 in the first embodiment.
[0109] When the user starts the print application on the information terminal 102, the CPU 302 of the information terminal 102 causes the display unit 308 to display a device selection screen 1100.
[0110] The device selection screen 1100 has a product name specification list box 1101 and a decision button 1102 arranged thereon, and the product name specification list box 1101 is used to specify the image forming device 101 that will perform printing.
[0111] When the enter button 1102 is pressed, the CPU 302 of the information terminal 102 saves the information of the image forming apparatus 101 specified in 1101 in the RAM 303 , generates a print setting screen 1103 , and displays it on the display unit 308 .
[0112] The print setting screen 1103 has a color mode specification list box 1104, a double-sided specification list box 1105, a service URL specification list box 1106, and a file selection button 1107. The color mode specification list box 1104 is used to specify the color mode when scanning. The double-sided specification list box 1105 is used to specify the setting of "single-sided printing" or "double-sided printing." The service URL specification list box 1106 is used to specify the service URL of the registration information stored in the storage 305. An example of a service URL is a cloud storage URL such as Google Drive (registered trademark) "https: / / cloud.Google.com." Another example of a service URL is a cloud storage URL such as OneDrive (registered trademark) "https: / / www.microsoft.com / onedrive."
[0113] When the file selection button 1107 is pressed, the CPU 302 of the information terminal 102 saves the print settings specified in 1104 to 1106 in the RAM 303. Then, the CPU 302 sends HTTP request data of a first authentication request to the selected service URL, together with the user ID and password of the registration information corresponding to the service URL and a read authority request for requesting reading from the cloud server.
[0114] When HTTP response data indicating authentication failure is received in response to the first authentication request, the CPU 302 of the information terminal 102 displays on the display unit 308 a print setting screen 1103 on which an error message is displayed based on the received error content.
[0115] When HTTP response data indicating successful transmission is received in response to the HTTP request data of the first authentication request, the CPU 302 of the information terminal 102 causes the display unit 308 to display a one-time password entry screen 1108 .
[0116] The one-time password input screen 1108 is provided with a one-time password input text box 1109, a send button 1110, and a close button 1111. When the user inputs a one-time password in the one-time password input text box and presses the send button 1110, the CPU 302 of the information terminal 102 transmits HTTP request data to the cloud server 103. The input one-time password is added to this HTTP request data, and this HTTP request data is transmitted.
[0117] When HTTP response data indicating authentication failure is received in response to the second authentication request, the CPU 302 of the information terminal 102 displays on the display unit 308 a one-time password input screen 1108 on which an error message is displayed based on the received error content.
[0118] When HTTP response data indicating successful authentication is received in response to the first authentication request, or when HTTP response data indicating successful authentication is received in response to the second authentication request, the CPU 302 of the information terminal 102 causes the display unit 308 to display a file selection screen 1112.
[0119] The file selection screen 1112 has a file list 1113, a print start button 1114, and a cancel button 1115 arranged thereon, and a list of files stored in the service URL is displayed in the file list 1113. The user can select each file in the file list 1113 using the operation unit 307. When the user presses the print start button 1114 with one or more files selected, the CPU 302 of the information terminal 102 transmits a print job ticket to the image forming apparatus 101. The CPU 302 also displays a print start screen 1116 on the display unit 308. When the user presses the close button 1111, the CPU 302 of the information terminal 102 terminates the print application. Upon receiving the print job ticket, the image forming apparatus 101 executes a print job in accordance with the received print job ticket. Specifically, the CPU 202 executes a reception process to receive the selected file from the cloud server 103 indicated by the URL specified in the service URL specification list box 1106. Then, the CPU 202 causes the print engine 210 to print the selected file based on the print settings set in the color mode designation list box 1104 and the double-sided designation list box 1105 on the print setting screen 1103 . A close button 1111 is arranged on the print start screen 1116, and when the user presses the close button 1111, the CPU 302 of the information terminal 102 ends the print application.
[0120] <Scan sequence> FIG. 12 is a sequence diagram showing an example of a means for authenticating the cloud server 103 using two-step authentication and executing a scan job to transmit an image to the cloud server 103 in the first embodiment of the present invention. Each process in the flowchart of FIG. 12 is performed by the CPU 402 of the cloud server 103 reading a program stored in the ROM 404 into the RAM 403 and executing it. In this embodiment, a scan job execution means is described when two-step authentication is performed from the information terminal 102 before executing a scan job in a setting where two-step authentication is required for write permission to the cloud server 103. In this embodiment, the information terminal 102, the image forming apparatus 101, the cloud server 103, and the authentication server 104 each communicate using HTTP. In addition, when sending a one-time password from the authentication server 104 to the information terminal 102, it is sent by SMS using a public line, and the information terminal 102 and the cloud server 103 perform primary authentication using Basic authentication.
[0121] In step S1201, the user designates a device on the device selection screen 1000 of the scan application on the information terminal 102, and sets the scan job on the scan setting screen 1003, and then presses the start scan button 1008 on the scan setting screen 1003.
[0122] In S1202, the CPU 202 of the information terminal 102 transmits a first authentication request to the cloud server 103 corresponding to the service URL "https: / / aaa.com / Storage1" set in S1201. This first authentication request is transmitted with the user ID "user1" and password "password1" corresponding to the service URL stored in the storage 305 attached.
[0123] In S1203, the CPU 402 of the cloud server 103 redirects the HTTP POST request received in S1202 to the authentication server 104.
[0124] In S1204, the CPU 502 of the authentication server 104 executes the first authentication process (FIG. 9(A)).
[0125] In S1205, the CPU 502 of the authentication server 104 transmits HTTP response data with an HTTP response status code of "200" and a detailed status of "transmission result notification" to the cloud server 103 as a response to the first authentication request.
[0126] In S1206, the CPU 402 of the cloud server 103 redirects the HTTP response data received in S1205 to the information terminal 102.
[0127] In step S1207, the CPU 302 of the information terminal 102 displays the one-time password entry screen 1009 on the display unit 308.
[0128] In S1208, the CPU 502 of the authentication server 104 sends the one-time password "1111" generated in the first authentication process by SMS to the information terminal 102 via the public line 106. Here, the information terminal 102 has been used as an example of the destination of the one-time password "1111", but the one-time password "1111" may also be sent by SMS to another device registered in association with the user.
[0129] In S1209, the CPU 302 of the information terminal 102 displays the one-time password "1111" received in S1207 on the display unit 308 via an SMS application (not shown).
[0130] In step S1210, the user enters the one-time password "1111" confirmed in step S1209 into the one-time password entry screen 1009 using the operation unit 307 of the information terminal 102, and presses the send button 1011.
[0131] In S1211, the CPU 302 of the information terminal 102 sends a second authentication request, to which the one-time password "1111" input in S1210 has been added, as an HTTP POST request to the cloud server 103. Note that if the one-time password "1111" has been sent to another device, the information terminal 102 in S1210 and S1211 can be read as the other device.
[0132] In S1212, the CPU 402 of the cloud server 103 redirects the HTTP POST request received in S1211 to the authentication server 104.
[0133] In S1213, the CPU 502 of the authentication server 104 executes the second authentication process (FIG. 9(B)).
[0134] In S1214, the CPU 502 of the authentication server 104 transmits HTTP response data to the cloud server 103. This HTTP response data is transmitted with the HTTP response status code "200" as a response to the second authentication request, the detailed status "authentication successful", and the authentication information "dXNlcjE6cGFzc3dvcmQx" attached thereto.
[0135] In step S1215, the CPU 402 of the cloud server 103 redirects the HTTP response data received in step S1214 to the information terminal 102.
[0136] In S1216, the CPU 302 of the information terminal 102 generates a job command. This job command is generated based on the scan job settings set in S1201, the service URL "https: / / aaa.com / Storage1," and the authentication information "dXNlcjE6cGFzc3dvcmQx" received in S1215. Then, the CPU 302 transmits a scan job ticket (FIG. 13) to the image forming apparatus 101 specified in S1201.
[0137] In step S1217, the CPU 202 of the image forming apparatus 101 generates a scan job based on the scan job settings received in step S1216, and starts the scan job.
[0138] In step S1218, the CPU 202 of the image forming apparatus 101 transmits to the information terminal 102 HTTP response data with the HTTP response status code "200" to which "job in progress", which indicates the status of the scan job being executed, has been added.
[0139] In S1219, when the CPU 302 of the information terminal 102 receives "Job in progress" as a result of successful scan job generation, it displays the scanning screen 1013 on the display unit 308 and starts a status monitoring process that monitors the status of the image forming device 101 every 100 msec.
[0140] In step S1220, the CPU 302 of the information terminal 102 sends an HTTP POST request to the image forming apparatus 101 to acquire the status.
[0141] In S1221, the CPU 202 of the image forming apparatus 101 receives the HTTP POST request for status acquisition in S1220 before completing the transmission of the image data. In response, the CPU 202 executes processing to transmit HTTP response data with the HTTP response status code "200" and the job status "Job in progress" to the information terminal 102. Here, the CPU 302 of the information terminal 102 continues to display the scanning screen 1013 while the job status received in S1221 is "Job in progress".
[0142] When the scan job of the image forming apparatus 101 is completed, in S1222, the CPU 202 of the image forming apparatus 101 sends an HTTPS POST request. The authentication information received in S1216 is attached to this HTTPS POST request. The message body of the HTTPS POST request contains binary data of the scanned image. This HTTPS POST request is then sent to the destination of the cloud server 103 received in S1216. In this case, the destination of the cloud server 103 is "https: / / aaa.com / Storage1". The authentication information received in S1216 is "dXNlcjE6cGFzc3dvcmQx".
[0143] When the transfer of the image data is completed, the process proceeds to S1223. In S1223, the CPU 402 of the cloud server 103 transmits HTTPS response data with an HTTPS response status code of "200" indicating the image data transmission result "transmission successful" to the information terminal 102 as a response to the image data transmission.
[0144] In step S1224, the CPU 302 of the information terminal 102 sends an HTTP POST request to the image forming apparatus 101 to acquire the status.
[0145] In step S1225, the CPU 202 of the image forming apparatus 101 receives the HTTP POST request for the status acquisition request in step S1220 after the scan job is completed. In response, the CPU 202 of the image forming apparatus 101 transmits HTTP response data with the HTTP response status code "200" and the job status "transmission successful" to the information terminal 102. In S1226, the CPU 302 of the information terminal 102 determines that the transmission of the scanned image was successful based on the job status "transmission successful" in the response data received in S1225, and causes the display unit 308 to display the transmission success screen 1015.
[0146] <Scan app execution process> 14 is a diagram showing a flowchart of scan application execution processing showing scan execution processing of the scan application of the information terminal 102 in Example 1. Each process in the flowchart of FIG. 14 is performed by the CPU 302 of the information terminal 102 reading a program stored in the ROM 304 into the RAM 303 and executing it. Before starting this process, it is assumed that the service URL registration process (FIG. 8) has been executed and the service URL information has been saved in the storage 305.
[0147] When the user presses the start scan button 1008 after specifying the color mode, resolution, input method, and service URL on the scan setting screen 1003, the CPU 302 of the information terminal 102 executes the first authentication process (FIG. 14(A)).
[0148] In step S1401 , the CPU 302 of the information terminal 102 stores in the RAM 303 the color mode designation, resolution designation, input method, and service URL that were set on the scan setting screen 1003 .
[0149] In step S1402, the CPU 302 of the information terminal 102 sends a first authentication request by HTTP POST request to the cloud server 103 corresponding to the service URL set on the scan setting screen 1003. The first authentication request is sent with the user ID and password corresponding to the service URL stored in the storage 305 attached.
[0150] In S1403, if the HTTP response status code in the response to the first authentication request sent in S1402 is "401", the CPU 302 of the information terminal 102 determines that the authentication has failed.
[0151] If the determination result in S1403 is not authentication failure, in S1404 the CPU 302 of the information terminal 102 determines that a one-time password is required if the detailed status of the response to the first authentication request sent in S1402 is "transmission result notification."
[0152] If the result of the determination in S1404 is that a one-time password is necessary, the CPU 302 of the information terminal 102 displays the one-time password input screen 1009 on the display unit 308 in S1405.
[0153] If the determination result in S1403 is authentication failure, in S1406, the CPU 302 of the information terminal 102 displays the scan setting screen 1003 on the display unit 308, which displays an error message based on the error content obtained in response to the first authentication request sent in S1402.
[0154] If the determination result in S1404 is that a one-time password is not required, the CPU 302 of the information terminal 102 stores in the RAM 303 the authentication information acquired in response to the first authentication request.
[0155] In S1408, the CPU 302 of the information terminal 102 executes the scan execution process (FIG. 14C).
[0156] When the user presses the send button 1011 after inputting the one-time password on the one-time password input screen 1009, the CPU 302 of the information terminal 102 executes the second authentication process (FIG. 14(B)).
[0157] In step S1409, the CPU 302 of the information terminal 102 sends a second authentication request, to which the one-time password entered on the one-time password entry screen 1009 has been added, to the cloud server 103 as an HTTP POST request.
[0158] In step S1410, the CPU 302 of the information terminal 102 determines that the authentication has failed if the HTTP response status code in the response to the second authentication request sent in step S1409 is "401."
[0159] If the determination result in S1410 is not authentication failure, the CPU 302 of the information terminal 102 stores the authentication information acquired in response to the second authentication request in the RAM 303 in S1411.
[0160] In S1412, the CPU 302 of the information terminal 102 executes the scan execution process (FIG. 14C).
[0161] If the determination result in S1410 is authentication failure, in S1413, the CPU 302 of the information terminal 102 displays on the display unit 308 the one-time password input screen 1009 with an error message based on the error content obtained in response to the second authentication request sent in S1409.
[0162] The CPU 302 of the information terminal 102 executes the scan execution process (FIG. 14C) in steps S1408 and S1412.
[0163] In step S1414, the CPU 302 of the information terminal 102 generates a scan job ticket (FIG. 13) based on the color mode designation, resolution designation, input method, service URL, and authentication information stored in the RAM 303. The CPU 302 then executes processing to transmit the scan job ticket to the image forming apparatus 101 using an HTTP POST request.
[0164] In step S1415, the CPU 302 of the information terminal 102 displays the scanning screen 1013 on the display unit 308.
[0165] In step S1416, the CPU 302 of the information terminal 102 sends a status acquisition request to the image forming apparatus 101 using an HTTP POST request, with the job ID acquired in response to the scan job ticket sent in step S1414 attached.
[0166] If the job status in the response to the status acquisition request sent in S1417 is "job in progress", it is determined that the job is in progress, and if the job is in progress, the CPU 302 of the information terminal 102 executes S1416 again after 100 msec.
[0167] If the determination result in step S1417 is that the job is not currently being executed, then in step S1418, the CPU 302 of the information terminal 102 determines that the transmission was successful if the job status in the response to the status acquisition request transmitted in step S1417 is "transmission successful."
[0168] If it is determined in S1418 that the transmission was successful, the CPU 302 of the information terminal 102 displays a transmission success screen 1015 on the display unit 308 in S1419.
[0169] If it is determined in S1418 that the transmission was not successful, the CPU 302 of the information terminal 102 displays the error screen 1016 on the display unit 308 in S1420.
[0170] <Scanning process of the first image forming device> Fig. 15 is a diagram showing a flowchart of scan processing by the image forming apparatus 101 in the first embodiment. Each process in the flowchart in Fig. 15 is performed by the CPU 202 of the image forming apparatus 101 reading a program stored in the ROM 204 into the RAM 203 and executing the program. When a scan job ticket is received from the information terminal 102 by an HTTP POST request, the CPU 202 of the image forming apparatus 101 starts the scan processing (Fig. 15).
[0171] In step S1501 , the CPU 202 of the image forming apparatus 101 generates job information including a job ID that is an ID indicating a job based on the scan job ticket, and stores the job information in the storage 205 .
[0172] In step S1502, the CPU 202 of the image forming apparatus 101 sends HTTP response data with the HTTP response status code "200" as a response to the scan job ticket, with the job ID of the scan job added.
[0173] In step S1503, the CPU 202 of the image forming apparatus 101 executes scanning based on the scan job information generated in step S1501. The scanned image is then stored in the storage 205 as scanned image data.
[0174] In step S1504, if the execution result of the scan job is "success", the CPU 202 of the image forming apparatus 101 determines that the scan was successful.
[0175] If it is determined in step S1504 that the scan was successful, the CPU 202 of the image forming apparatus 101 sends an image data transmission notification by an HTTP POST request in step S1505. This image data transmission notification is sent to the cloud server 103 with the scanned image data in the storage 205 attached based on the service URL and authentication information of the scan job ticket.
[0176] In step S1506, the CPU 202 of the image forming apparatus 101 determines that the transmission was successful if the transmission result of the response to the image data transmission notification transmitted in step S1505 is "successful transmission."
[0177] If it is determined in S1506 that the transmission was successful, in S1507 the CPU 202 of the image forming apparatus 101 saves the job status "transmission successful" in the job information of the storage 205 corresponding to the job ID of the job executed in S1503. The saved job status is sent to the information terminal 102 as a response to the status acquisition request in S1417.
[0178] If it is determined in step S1506 that the transmission was not successful, in step S1508 the CPU 202 of the image forming apparatus 101 saves the job status "transmission failed" in the job information in the storage 205 corresponding to the job ID of the job executed in step S1503.
[0179] If it is determined in step S1504 that the scan was not successful, in step S1508 the CPU 202 of the image forming apparatus 101 stores the job status "scan failed" in the job information in the storage 205 corresponding to the job ID of the job executed in step S1503.
[0180] <Print sequence> 16 is a sequence diagram showing an example of a means for authenticating the cloud server 103 using two-step authentication in the first embodiment of the present invention, and executing a print job for acquiring and printing an image stored in the cloud server 103. In this embodiment, a print job execution means is described for performing two-step authentication from the information terminal 102 before executing a print job, with the cloud server 103 set to require two-step authentication for read privileges. In this embodiment, the information terminal 102, the image forming apparatus 101, the cloud server 103, and the authentication server 104 each communicate using HTTP. When the authentication server 104 sends a one-time password to the information terminal 102, it is sent by SMS using a public line, and the information terminal 102 and the cloud server 103 perform primary authentication using Basic authentication.
[0181] In step S1601, the user designates a device on the device selection screen 1100 of the print application on the information terminal 102 and sets a print job on the print setting screen 1103, and then presses the file selection button 1107 on the print setting screen 1103.
[0182] In S1602, the CPU 202 of the information terminal 102 sends a first authentication request to the cloud server 103 corresponding to the service URL set in S1601 using an HTTP POST request. This first authentication request is sent with the user ID "user1" and password "password1" corresponding to the service URL stored in the storage 305. The service URL here is "https: / / aaa.com / Storage1".
[0183] In S1603, the CPU 402 of the cloud server 103 redirects the HTTP POST request received in S1602 to the authentication server 104.
[0184] In S1604, the CPU 502 of the authentication server 104 executes the first authentication process (FIG. 9A).
[0185] In S1605, the CPU 502 of the authentication server 104 transmits HTTP response data with an HTTP response status code of "200" and a detailed status of "transmission result notification" to the cloud server 103 as a response to the first authentication request.
[0186] In S1606, the CPU 402 of the cloud server 103 redirects the HTTP response data received in S1605 to the information terminal 102.
[0187] In step S1607, the CPU 302 of the information terminal 102 displays a one-time password input screen 1108 on the display unit 308.
[0188] In S1608, the CPU 502 of the authentication server 104 transmits the one-time password "1111" generated in the first authentication process to the information terminal 102 via the public line 106 by SMS.
[0189] In S1609, the CPU 302 of the information terminal 102 displays the one-time password "1111" received in S1607 on the display unit 308 via an SMS application (not shown).
[0190] In step S1610, the user enters the one-time password "1111" confirmed in step S1609 into the one-time password entry screen 1108 using the operation unit 307 of the information terminal 102, and presses the send button 1110.
[0191] In S1611, the CPU 302 of the information terminal 102 sends a second authentication request to the cloud server 103, to which the one-time password "1111" input in S1610 has been added, using an HTTP POST request.
[0192] In S1612, the CPU 402 of the cloud server 103 redirects the HTTP POST request received in S1611 to the authentication server 104.
[0193] In S1613, the CPU 502 of the authentication server 104 executes the second authentication process (FIG. 9B). In S1614, the CPU 502 of the authentication server 104 transmits HTTP response data to the cloud server 103 as a response to the second authentication request. This HTTP response data is transmitted with the HTTP response status code "200", a detailed status of "authentication successful", and authentication information "dXNlcjE6cGFzc3dvcmQx".
[0194] In step S1615, the CPU 402 of the cloud server 103 redirects the HTTP response data received in step S1614 to the information terminal 102.
[0195] In S1616, the CPU 302 of the information terminal 102 sends a file acquisition request to the cloud server 103 using an HTTP POST request, with the service URL set in S1601 and the authentication information acquired in S1615 attached. In this example, the service URL set in the cloud server 103 in S1601 is "https: / / aaa.com / Storage1". In addition, the authentication information acquired in S1615 is "dXNlcjE6cGFzc3dvcmQx".
[0196] In S1617, the CPU 402 of the cloud server 103 transmits HTTP response data to the information terminal 102, to which the file names stored in the service URL have been added, as a response to the file acquisition request. In this example, the service URL is "https: / / aaa.com / Storage1". The file names are "aaa.jpg" and "bbb.pdf".
[0197] In S1618, the CPU 302 of the information terminal 102 causes the display unit 308 to display a file selection screen 1112 that displays the file names "aaa.jpg" and "bbb.pdf" acquired in S1617 as a file list 1113.
[0198] In step S1619, the user selects the file “aaa.jpg” from the file list 1113 on the operation unit 307 of the information terminal 102 and presses the print start button 1114.
[0199] In S1620, CPU 302 generates a job command based on the print job settings set in S1601, a file URL formed by combining the service URL set in S1601 and the file name selected in S1619, and the authentication information received in S1615. In this example, the service URL is "https: / / aaa.com / Storage1." The file URL is "https: / / aaa.com / Storage1 / aaa.pdf." The authentication information is "dXNlcjE6cGFzc3dvcmQx." CPU 302 then executes processing to transmit the print job ticket (FIG. 17) to the image forming apparatus 101 specified in S1601.
[0200] In step S1621, the CPU 302 of the information terminal 102 displays a print start screen 1116 on the display unit 308.
[0201] In step S1622, the CPU 202 of the image forming apparatus 101 sends to the cloud server 103 an image data acquisition request to which the file URL received in step S1620 and authentication information have been added, using an HTTP POST request.
[0202] In step S1623, the CPU 302 of the cloud server 103 transmits HTTP response data to the information terminal 102, to which the image data of the file specified by the file URL has been added, as a response to the image data acquisition request.
[0203] In step S1624, the CPU 202 of the image forming apparatus 101 generates a print job based on the print job settings received in step S1620, and starts printing the image data acquired in step S1622.
[0204] <Print application execution process> 18 is a diagram showing a flowchart of print application execution processing showing print execution processing of the print application of the information terminal 102 in Example 1. Each process in the flowchart of FIG. 18 is performed by the CPU 302 of the information terminal 102 reading a program stored in the ROM 304 into the RAM 303 and executing it. Before starting this processing, it is assumed that the service URL registration processing (FIG. 8) is performed and the service URL information is saved in the storage 305.
[0205] When the user presses the file selection button 1107 after specifying the color mode, double-sided printing, and service URL on the print setting screen 1103, the CPU 302 of the information terminal 102 executes the first authentication process (FIG. 18(A)).
[0206] In step S1801, the CPU 302 of the information terminal 102 stores in the RAM 303 the color mode designation, resolution designation, input method, and service URL that were set on the print setting screen 1103.
[0207] In step S1802, the CPU 302 of the information terminal 102 sends a first authentication request by HTTP POST request to the cloud server 103 corresponding to the service URL set on the print setting screen 1103. The first authentication request is sent together with the user ID and password corresponding to the service URL stored in the storage 305.
[0208] In S1803, if the HTTP response status code in the response to the first authentication request sent in S1802 is "401", the CPU 302 of the information terminal 102 determines that the authentication has failed.
[0209] If the determination result in S1803 is not authentication failure, in S1804 the CPU 302 of the information terminal 102 determines that a one-time password is required if the detailed status of the response to the first authentication request sent in S1802 is "transmission result notification."
[0210] If the result of the determination in S1804 is that a one-time password is necessary, the CPU 302 of the information terminal 102 displays a one-time password input screen 1108 on the display unit 308 in S1805.
[0211] If the determination result in S1803 is authentication failure, in S1806, the CPU 302 of the information terminal 102 displays the print setting screen 1103 on the display unit 308, which displays an error message based on the error content obtained in response to the first authentication request sent in S1802.
[0212] If the determination result in S1804 is that a one-time password is not required, in S1807 the CPU 302 of the information terminal 102 stores in the RAM 303 the authentication information acquired in response to the first authentication request.
[0213] In step S1808, the CPU 302 of the information terminal 102 sends a file acquisition request by HTTP POST request, adding the service URL acquired in step S1801 and the authentication information acquired in step S1807.
[0214] In step S1809, the CPU 302 of the information terminal 102 causes the display unit 308 to display a file selection screen 1112 that displays, as a file list 1113, the file names assigned in the response to the file acquisition request sent in step S1807.
[0215] When the user presses the send button 1110 after entering the one-time password on the one-time password entry screen 1108, the CPU 302 of the information terminal 102 executes the second authentication process (FIG. 18(B)).
[0216] In step S1810, the CPU 302 of the information terminal 102 sends a second authentication request, to which the one-time password entered on the one-time password entry screen 1108 has been added, to the cloud server 103 as an HTTP POST request.
[0217] In step S1811, the CPU 302 of the information terminal 102 determines that the authentication has failed if the HTTP response status code in the response to the second authentication request sent in step S1810 is "401."
[0218] If the determination result in S1811 is not authentication failure, the CPU 302 of the information terminal 102 stores in the RAM 303 in S1812 the authentication information acquired in response to the second authentication request.
[0219] In step S1813, the CPU 302 of the information terminal 102 sends a file acquisition request by HTTP POST request, together with the service URL stored in the RAM 303 and the authentication information.
[0220] In step S1814, the CPU 302 of the information terminal 102 displays on the display unit 308 a file selection screen 1112 that displays, as a file list 1113, the file names assigned in the response to the file acquisition request sent in step S1813.
[0221] If the determination result in S1811 is authentication failure, in S1815 the CPU 302 of the information terminal 102 displays on the display unit 308 a one-time password input screen 1108 containing an error message based on the error content obtained in response to the second authentication request sent in S1811.
[0222] When the user selects a file name from the file list 1113 on the file selection screen 1112 and then presses the print start button 1114, a print execution process (FIG. 18(C)) is executed.
[0223] In S1816, the CPU 302 of the information terminal 102 generates a print job ticket based on a file URL that combines the color mode designation, double-sided designation, and authentication information stored in the RAM 303, the service URL, and the file name selected in the file list 1113. An example of the print job ticket is shown in Fig. 17. Then, the CPU 302 transmits the generated print job ticket to the image forming apparatus 101 using an HTTP POST request.
[0224] In step S1817, the CPU 302 of the information terminal 102 displays a print start screen 1116 on the display unit 308.
[0225] <Print processing of image forming devices> Fig. 19 is a flowchart of print processing by the image forming apparatus 101 in the embodiment 1. Each process in the flowchart in Fig. 19 is performed by the CPU 202 of the image forming apparatus 101 reading a program stored in the ROM 204 into the RAM 203 and executing the program. When the CPU 202 of the image forming apparatus 101 receives a print job ticket from the information terminal 102 via an HTTP POST request, the CPU 202 of the image forming apparatus 101 starts scanning processing.
[0226] In step S1901, the CPU 202 of the image forming apparatus 101 sends an image data acquisition request, to which authentication information of the print job ticket has been added, to the cloud server 103 using an HTTP POST request based on the file URL of the print job ticket.
[0227] In step S1902, the CPU 302 of the image forming apparatus 101 determines that the acquisition was successful if the HTTP response status code in response to the image data acquisition request sent in step S1901 is "200."
[0228] If it is determined in step S1902 that the acquisition was successful, the CPU 302 of the image forming apparatus 101 proceeds to step S1903. In step S1903, the CPU 202 generates print job information including the image data attached to the response to the image data acquisition request sent in step S1901 and a job ID that is an ID indicating the job based on the print job ticket, and saves the information in the storage 205.
[0229] In step S1904, the CPU 202 of the image forming apparatus 101 executes printing based on the print job information generated in step S1903.
[0230] If it is determined in step S1902 that the acquisition was not successful, the CPU 202 of the image forming apparatus 101 displays an error screen on the operation panel 208 in step S1905.
[0231] In this embodiment, the first scan control sequence and print control sequence are shown as methods for controlling the image forming apparatus using authentication information acquired through two-step authentication, but the present invention is not limited to this.
[0232] By performing two-step authentication as described above, the image forming device can receive control instructions only from the information terminal used by the user, thereby making it possible to prevent spoofing.
[0233] <Example 2> <Sequence of first scan and authentication in parallel> 20 is a sequence diagram showing an example of a case in which authentication of the cloud server 103 using two-step authentication and an instruction for a scan job to transmit an image to the cloud server 103 are simultaneously performed, and the scan job ends first, in Example 2 of the present invention. In this example, a scan job execution means is described when two-step authentication is performed from the information terminal 102 before executing a scan job, with the cloud server 103 set to require two-step authentication with write authority. In this example, the information terminal 102, the image forming apparatus 101, the cloud server 103, and the authentication server 104 each communicate using HTTP. When the authentication server 104 sends a one-time password to the information terminal 102, it is sent by SMS using a public line, and the information terminal 102 and the cloud server 103 perform primary authentication using Basic authentication.
[0234] In step S2001, the user designates a device from the device selection screen 1000 in the scan application on the information terminal 102, and sets the scan job on the scan setting screen 1003. Then, the user presses the start scan button 1008 on the scan setting screen 1003.
[0235] In S2002, the CPU 302 of the information terminal 102 generates a job command based on the scan job settings set in S2001 and the service URL "https: / / aaa.com / Storage1" set in S2001. Then, the CPU 302 of the information terminal 102 executes processing to transmit the scan job ticket (FIG. 22) to the image forming apparatus 101 specified in S2001.
[0236] In step S2003, the CPU 202 of the image forming apparatus 101 generates a job based on the scan job ticket received in step S2002. The CPU 202 then executes processing to transmit to the information terminal 102 a job ID that is the ID of the generated job, and HTTP response data with an HTTP response status code of "200" that includes "scan successful," indicating that the scan job has been executed.
[0237] In step S2004, the CPU 202 of the image forming apparatus 101 starts a scan job based on the scan job generated in step S2003.
[0238] In S2005, the CPU 202 of the information terminal 102 sends a first authentication request by HTTP POST request to the cloud server 103 corresponding to the service URL "https: / / aaa.com / Storage1" set in S2001. This first authentication request is sent with the user ID "user1" and password "password1" corresponding to the service URL stored in the storage 305 attached.
[0239] In S2006, the CPU 402 of the cloud server 103 redirects the HTTP POST request received in S2003 to the authentication server 104.
[0240] In S2007, the CPU 502 of the authentication server 104 executes the first authentication process (FIG. 9(A)).
[0241] In S2008, the CPU 502 of the authentication server 104 transmits HTTP response data with an HTTP response status code of "200" and a detailed status of "transmission result notification" to the cloud server 103 as a response to the first authentication request.
[0242] In step S2009, the CPU 402 of the cloud server 103 redirects the HTTP response data received in step S2007 to the information terminal 102.
[0243] In step S2010, the CPU 302 of the information terminal 102 displays the one-time password entry screen 1009 on the display unit 308.
[0244] In step S2011, the CPU 502 of the authentication server 104 transmits the one-time password "1111" generated in the first authentication process to the information terminal 102 via the public line 106 as an SMS.
[0245] In S2012, the CPU 302 of the information terminal 102 displays the one-time password "1111" received in S2011 on the display unit 308 via an SMS application (not shown).
[0246] In step S2013, the user enters the one-time password "1111" displayed in step S2012 into the one-time password entry screen 1009 using the operation unit 307 of the information terminal 102, and presses the send button 1011.
[0247] In S2014, the CPU 302 of the information terminal 102 sends a second authentication request to the cloud server 103, to which the one-time password "1111" input in S2013 has been added, using an HTTP POST request.
[0248] In S2015, the CPU 402 of the cloud server 103 redirects the HTTP POST request received in S2014 to the authentication server 104.
[0249] In S2016, the CPU 502 of the authentication server 104 executes the second authentication process (FIG. 9(B)).
[0250] In S2017, the CPU 502 of the authentication server 104 transmits HTTP response data as a response to the second authentication request to the cloud server 103. This HTTP response data is sent with the HTTP response status code "200", a detailed status of "authentication successful", and authentication information "dXNlcjE6cGFzc3dvcmQx".
[0251] In S2018, the CPU 402 of the cloud server 103 redirects the HTTP response data received in S2017 to the information terminal 102.
[0252] In S2019, the CPU 302 of the information terminal 102 generates an authentication command based on the job ID acquired in S2003, the service URL set in S2001, and the authentication information acquired in S2017. Then, the CPU 302 transmits an authentication ticket (FIG. 23) to the image forming apparatus 101 specified in S2001. In this example, the service URL set in S2001 is "https: / / aaa.com / Storage1". Furthermore, the authentication information acquired in S2017 is "dXNlcjE6cGFzc3dvcmQx".
[0253] In S2020, after transmitting the authentication ticket in S2019, the CPU 302 of the information terminal 102 displays the scanning screen 1013 on the display unit 308 and starts a status monitoring process for monitoring the status of the image forming apparatus 101 every 100 msec.
[0254] In S2021, the CPU 202 of the image forming apparatus 101 adds the authentication information received in S2019 to the HTTP header for the destination of the cloud server 103 received in S2019. Then, the CPU 202 executes a process of sending an HTTPS POST request with the binary data of the scanned image as the message body. In this example, the destination of the cloud server 103 is "https: / / aaa.com / Storage1". Furthermore, the authentication information received in S2019 is "dXNlcjE6cGFzc3dvcmQx".
[0255] In step S2022, the CPU 302 of the information terminal 102 transmits an HTTP POST request to the image forming apparatus 101 to acquire the status.
[0256] In S2023, the CPU 202 of the image forming apparatus 101 receives the HTTP POST request for the status acquisition request in S2022 before the transmission of the image data is completed. In response, the CPU 202 executes a process to transmit HTTP response data with the HTTP response status code "200" and the job status "scan successful" to the information terminal 102. Here, the CPU 202 of the information terminal 102 continues to display the scanning screen 1013 while the job status received in S2023 is "job in progress".
[0257] When the transfer of the image data is completed, the process proceeds to S2024. In S2024, the CPU 402 of the cloud server 103 transmits HTTPS response data with an HTTPS response status code of "200" to the information terminal 102 as a response to the image data transmission, the HTTPS response data indicating that the image data transmission result was "successful".
[0258] In step S2025, the CPU 302 of the information terminal 102 transmits an HTTP POST request to the image forming apparatus 101 to acquire the status.
[0259] In step S2026, the CPU 202 of the image forming apparatus 101 receives the HTTP POST request for the status acquisition request in step S2025 after the scan job is completed. Thereafter, the CPU 202 executes a process of transmitting HTTP response data with the HTTP response status code "200" and the job status "successful transmission" to the information terminal 102.
[0260] In S2027, the CPU 302 of the information terminal 102 determines that the transmission of the scanned image was successful based on the job status "transmission successful" in the response data received in S2026, and causes the display unit 308 to display a transmission success screen 1015.
[0261] <Sequence for parallel execution of second scan and authentication> 21 is a sequence diagram showing an example of a case in which authentication of the cloud server 103 using two-step authentication and an instruction for a scan job to transmit an image to the cloud server 103 are simultaneously performed using two-step authentication, and authentication is completed first, in Example 2 of the present invention. In this example, a scan job execution means is described when two-step authentication is performed from the information terminal 102 before executing a scan job, with the cloud server 103 set to require two-step authentication for write authority. In this example, the information terminal 102, the image forming apparatus 101, the cloud server 103, and the authentication server 104 each communicate using HTTP. In addition, when the authentication server 104 sends a one-time password to the information terminal 102, it is sent by SMS using a public line, and the information terminal 102 and the cloud server 103 perform primary authentication using Basic authentication.
[0262] In step S2101, the user designates a device on the device selection screen 1000 of the scan application on the information terminal 102, and sets the scan job on the scan setting screen 1003. Then, the user presses the start scan button 1008 on the scan setting screen 1003.
[0263] In S2102, the CPU 302 of the information terminal 102 generates a job command based on the scan job settings set in S2101 and the service URL set in S2101. Then, the CPU 302 executes processing to send the scan job ticket (FIG. 22) to the image forming apparatus 101 specified in S2101. In this example, the service URL set in S2101 is "https: / / aaa.com / Storage1".
[0264] In step S2103, the CPU 202 of the image forming apparatus 101 generates a job based on the scan job ticket received in step S2102. Then, the CPU 202 transmits to the information terminal 102 HTTP response data with an HTTP response status code of "200" to which is added a job ID that is the ID of the generated job and "job in progress," which indicates the status in which the scan job is being executed.
[0265] In step S2104, the CPU 202 of the image forming apparatus 101 starts a scan job based on the scan job generated in step S2103.
[0266] In S2105, the CPU 202 of the information terminal 102 sends a first authentication request by HTTP POST request to the cloud server 103 corresponding to the service URL "https: / / aaa.com / Storage1" set in S2101. This first authentication request is sent with the user ID "user1" and password "password1" corresponding to the service URL stored in the storage 305.
[0267] In S2106, the CPU 402 of the cloud server 103 redirects the HTTP POST request received in S2103 to the authentication server 104.
[0268] In S2107, the CPU 502 of the authentication server 104 executes the first authentication process (FIG. 9A).
[0269] In S2108, the CPU 502 of the authentication server 104 transmits HTTP response data with an HTTP response status code of "200" and a detailed status of "transmission result notification" to the cloud server 103 as a response to the first authentication request.
[0270] In step S2109, the CPU 402 of the cloud server 103 redirects the HTTP response data received in step S2107 to the information terminal 102.
[0271] In step S2110, the CPU 302 of the information terminal 102 displays the one-time password entry screen 1009 on the display unit 308.
[0272] In S2111, the CPU 502 of the authentication server 104 transmits the one-time password "1111" generated in the first authentication process to the information terminal 102 via the public line 106 by SMS.
[0273] In S2112, the CPU 302 of the information terminal 102 displays the one-time password "1111" received in S2111 on the display unit 308 via an SMS application (not shown).
[0274] In step S2113, the user enters the one-time password "1111" displayed in step S2112 into the one-time password entry screen 1009 using the operation unit 307 of the information terminal 102, and presses the send button 1011.
[0275] In S2114, the CPU 302 of the information terminal 102 sends a second authentication request to the cloud server 103, to which the one-time password "1111" input in S2113 has been added, using an HTTP POST request.
[0276] In S2115, the CPU 402 of the cloud server 103 redirects the HTTP POST request received in S2114 to the authentication server 104.
[0277] In S2116, the CPU 502 of the authentication server 104 executes the second authentication process (FIG. 9B).
[0278] In S2117, the CPU 502 of the authentication server 104 sends HTTP response data to the cloud server 103 as a response to the second authentication request, including an HTTP response status code, a detailed status of "authentication successful," and authentication information. In this example, the HTTP response status code is "200." The authentication information is "dXNlcjE6cGFzc3dvcmQx."
[0279] In step S2118, the CPU 402 of the cloud server 103 redirects the HTTP response data received in step S2117 to the information terminal 102.
[0280] In S2119, the CPU 302 of the information terminal 102 generates an authentication command based on the job ID acquired in S2103, the service URL set in S2101, and the authentication information "dXNlcjE6cGFzc3dvcmQx" acquired in S2117. Then, the CPU 202 executes a process to transmit the authentication ticket (FIG. 23) to the image forming apparatus 101 specified in S2101. In this example, the service URL is "https: / / aaa.com / Storage1".
[0281] In S2120, after transmitting the authentication ticket in S2119, the CPU 302 of the information terminal 102 displays the scanning screen 1013 on the display unit 308 and starts a status monitoring process for monitoring the status of the image forming apparatus 101 every 100 msec.
[0282] In step S2121, the CPU 302 of the information terminal 102 sends an HTTP POST request to the image forming apparatus 101 to acquire the status.
[0283] In S2122, the CPU 202 of the image forming apparatus 101 receives an HTTP POST request for a status acquisition request in 2321 before completing the transmission of the image data. Thereafter, the CPU 202 executes processing to transmit HTTP response data with an HTTP response status code of "200" and with the job status "job in progress" assigned to it to the information terminal 102. Here, the CPU 202 of the information terminal 102 continues to display the scanning screen 1013 while the job status received in S2122 is "job in progress."
[0284] When the scan job is completed, in S2123, the CPU 202 of the image forming apparatus 101 sends an HTTPS POST request to the destination "https: / / aaa.com / Storage1" of the cloud server 103 received in S2119. Specifically, the CPU 202 adds the authentication information "dXNlcjE6cGFzc3dvcmQx" received in S2119 to the HTTP header, and sends an HTTPS POST request with the binary data of the scanned image as the message body.
[0285] When the transfer of the image data is completed, the process proceeds to S2124. In S2124, the CPU 402 of the cloud server 103 transmits HTTPS response data with an HTTPS response status code of "200" indicating the image data transmission result "transmission successful" to the information terminal 102 as a response to the image data transmission.
[0286] In step S2125, the CPU 302 of the information terminal 102 sends an HTTP POST request to the image forming apparatus 101 to acquire the status.
[0287] In step S2126, the CPU 202 of the image forming apparatus 101 receives the HTTP POST request for the status acquisition request in step S2125 after the scan job is completed. Thereafter, the CPU 202 executes a process of transmitting HTTP response data with the HTTP response status code "200" and the job status "successful transmission" to the information terminal 102.
[0288] In step S2127, the CPU 302 of the information terminal 102 determines that the transmission of the scanned image was successful based on the job status "transmission successful" in the response data received in step S2126, and causes the display unit 308 to display the transmission success screen 1015.
[0289] <Scanning process of the second image forming device> Fig. 24 is a diagram showing a flowchart of scan processing by the image forming apparatus 101 in the second embodiment. Each process in the flowchart in Fig. 24 is performed by the CPU 202 of the image forming apparatus 101 reading a program stored in the ROM 204 into the RAM 203 and executing the program. When a scan job ticket is received from the information terminal 102 by an HTTP POST request, the CPU 202 of the image forming apparatus 101 starts the scan processing (Fig. 24(A)).
[0290] In step S2401 , the CPU 202 of the image forming apparatus 101 generates job information including a job ID that is an ID indicating the job based on the job settings and service URL transmitted in the scan job ticket, and stores the job information in the storage 205 .
[0291] In step S2402, the CPU 202 of the image forming apparatus 101 sends HTTP response data with the HTTP response status code "200" as a response to the scan job ticket, with the job ID of the scan job added.
[0292] In S2403, the CPU 202 of the image forming apparatus 101 executes scanning based on the scan job information generated in S2401. The scanned image is associated with the job ID generated in S2402 and stored in the storage 205 as scanned image data.
[0293] In step S2404, if the execution result of the scan job is "success", the CPU 202 of the image forming apparatus 101 determines that the scan was successful.
[0294] If it is determined in S2404 that the scan was successful, in S2405, if the primary authentication information in RAM 203 contains authentication information corresponding to the job ID generated in S2402, the CPU 202 of the image forming device 101 obtains the authentication information from the primary authentication information and determines that the authentication information has been received.
[0295] If it is determined in step S2405 that the authentication information has been received, in step S2406 the CPU 202 of the image forming apparatus 101 transmits an image data transmission notification to the cloud server 103 by an HTTP POST request based on the authentication information acquired in step S2405. This image data transmission notification is sent with the service URL of the scan job ticket and the scanned image data on the RAM 203 attached.
[0296] In step S2407, the CPU 202 of the image forming apparatus 101 determines that the transmission was successful if the transmission result of the response to the image data transmission notification transmitted in step S2406 is "successful transmission."
[0297] If it is determined in step S2407 that the transmission was successful, in step S2408 the CPU 202 of the image forming apparatus 101 stores the job status "transmission successful" in the job information in the storage 205 corresponding to the job ID of the job generated in step S2402.
[0298] If it is determined in step S2407 that the transmission was not successful, in step S2409 the CPU 202 of the image forming apparatus 101 stores the job status "transmission failed" in the job information in the storage 205 corresponding to the job ID of the job generated in step S2402.
[0299] If it is determined in step S2404 that the scan was not successful, in step S2410 the CPU 202 of the image forming apparatus 101 stores the job status "scan failed" in the job information in the storage 205 corresponding to the job ID of the job created in step S2402.
[0300] If it is determined in step S2405 that the authentication information has not been received, the CPU 202 of the image forming apparatus 101 stores in the RAM 203 in step S2412 the job ID of the job generated in step S2402 and the image scanned in step S2403.
[0301] In step S2412, the CPU 202 of the image forming apparatus 101 saves the job status "scan successful" in the job information in the storage 205 corresponding to the job ID of the job generated in step S2402.
[0302] When the authentication ticket is received from the information terminal 102 via an HTTP POST request, the CPU 202 of the image forming apparatus 101 starts the scan process (FIG. 24(B)).
[0303] In step S2412, the CPU 202 of the image forming apparatus 101 determines that scanning has been completed if the job status of the job information in the storage 205 corresponding to the job ID of the received authentication ticket is "scan successful." If it is determined in S2412 that scanning has been completed, the process proceeds to S2413. In S2413, the CPU 202 of the image forming apparatus 101 transmits an image data transmission notification using an HTTP POST request. This image data transmission notification is provided with a service URL stored in the job information of the storage 205 corresponding to the job ID acquired in the authentication ticket. In addition, this image data transmission notification is provided with the scanned image data stored in the storage 205 corresponding to the job ID acquired in the authentication ticket, which is sent to the cloud server 103 based on the authentication information in the authentication ticket.
[0304] In step S2414, the CPU 202 of the image forming apparatus 101 determines that the transmission was successful if the transmission result of the response to the image data transmission notification transmitted in step S2413 is "successful transmission."
[0305] If it is determined in step S2414 that the transmission was successful, in step S2415 the CPU 202 of the image forming apparatus 101 stores the job status "transmission successful" in the job information in the storage 205 corresponding to the job ID acquired in the authentication ticket.
[0306] If it is determined in step S2414 that the transmission was not successful, in step S2416 the CPU 202 of the image forming apparatus 101 stores the job status "transmission failed" in the job information in the storage 205 corresponding to the job ID acquired in the authentication ticket.
[0307] If it is determined in step S2412 that scanning has not been completed, then in step S2417 the CPU 202 of the image forming apparatus 101 determines that scanning has ended in an error if the job status of the job information in the storage 205 corresponding to the job ID of the received authentication ticket is "scan failed."
[0308] If it is determined in step S2418 that the scan has ended in an error, the CPU 202 of the image forming apparatus 101 stores the authentication information corresponding to the job ID of the received authentication ticket in the primary authentication information of the RAM 203.
[0309] <Sequence for parallel execution of third scan and authentication> 25 is a sequence diagram showing an example of a case in which authentication of the cloud server 103 using two-step authentication and an instruction for a scan job to transmit an image to the cloud server 103 are simultaneously performed, and a timeout error occurs while waiting for authentication information, in Example 2 of the present invention. In this example, a scan job execution means is described when two-step authentication is performed from the information terminal 102 before executing a scan job, with the cloud server 103 set to require two-step authentication with write authority. In this example, the information terminal 102, the image forming apparatus 101, the cloud server 103, and the authentication server 104 each communicate using HTTP. When the authentication server 104 sends a one-time password to the information terminal 102, it is sent by SMS using a public line, and the information terminal 102 and the cloud server 103 perform primary authentication using Basic authentication.
[0310] In step S2501, the user designates a device from the device selection screen 1000 in the scan application on the information terminal 102, and sets the scan job on the scan setting screen 1003. Then, the user presses the start scan button 1008 on the scan setting screen 1003.
[0311] In S2502, the CPU 302 of the information terminal 102 generates a job command based on the scan job settings set in S2501 and the service URL "https: / / aaa.com / Storage1" set in S2501. Then, the CPU 302 executes a process to transmit the scan job ticket (FIG. 22) to the image forming apparatus 101 specified in S2501.
[0312] In S2503, the CPU 202 of the image forming apparatus 101 generates a job based on the scan job ticket received in S2502. Then, the CPU 202 executes a process of transmitting to the information terminal 102 HTTP response data with an HTTP response status code of "200" to which is added a job ID that is the ID of the generated job and "job in progress," which indicates the status that the scan job is being executed.
[0313] In step S2504, the CPU 202 of the image forming apparatus 101 starts a scan job based on the scan job generated in step S2503.
[0314] In S2505, the CPU 202 of the information terminal 102 sends a first authentication request to the cloud server 103 corresponding to the service URL set in S2501 using an HTTP POST request. This first authentication request is sent with the user ID "user1" and password "password1" corresponding to the service URL stored in the storage 305. In this example, the service URL set in S2501 is "https: / / aaa.com / Storage1".
[0315] In S2506, the CPU 402 of the cloud server 103 redirects the HTTP POST request received in S2503 to the authentication server 104.
[0316] In S2507, the CPU 502 of the authentication server 104 executes the first authentication process (FIG. 9A).
[0317] In S2508, the CPU 502 of the authentication server 104 transmits HTTP response data with an HTTP response status code of "200" and a detailed status of "transmission result notification" to the cloud server 103 as a response to the first authentication request.
[0318] In S2509, the CPU 402 of the cloud server 103 redirects the HTTP response data received in S2507 to the information terminal 102.
[0319] In S2510, the CPU 302 of the information terminal 102 displays the one-time password entry screen 1009 on the display unit 308.
[0320] In S2511, the CPU 502 of the authentication server 104 transmits the one-time password "1111" generated in the first authentication process to the information terminal 102 via the public line 106 by SMS. In S2512, the CPU 302 of the information terminal 102 displays the one-time password "1111" received in S2511 on the display unit 308 via an SMS application (not shown).
[0321] In step S2513, the CPU 302 of the information terminal 102 transmits an HTTP POST request to the image forming apparatus 101 to acquire the status.
[0322] In S2514, the CPU 202 of the image forming apparatus 101 receives an HTTP POST request for a status acquisition request in 2713 before completing the transmission of the image data. In response, the CPU 202 executes processing to transmit HTTP response data with an HTTP response status code of "200" and with the job status "job in progress" assigned to it to the information terminal 102. Here, the CPU 302 of the information terminal 102 continues to display the scanning screen 1013 while the job status received in S2514 is "job in progress."
[0323] In S2515, the CPU 202 of the image forming apparatus 101 performs job cancellation processing if the timeout time specified in the scan job ticket has elapsed since the scan job ticket was received in S2501 and an authentication ticket has not been received. Then, the CPU 202 sets the job status of the job information corresponding to the job ID of the scan job ticket received in S2501 to "job failed." In this embodiment, since the timeout time is specified as 300 in the scan job ticket example of FIG. 22, job cancellation is performed if the authentication ticket has not been received 300 seconds after S2501. Because there is a possibility that a user will enter a one-time password and send an authentication ticket before the one-time password expiration date, it is desirable to determine the timeout time so that the time after the timeout time has elapsed is later than the one-time password expiration date.
[0324] In step S2516, the CPU 302 of the information terminal 102 transmits an HTTP POST request to the image forming apparatus 101 to acquire the status.
[0325] In step S2517, the CPU 202 of the image forming apparatus 101 transmits to the information terminal 102 HTTP response data with the job status "scan failed" and the HTTP response status code "200".
[0326] In S2518, the CPU 302 of the information terminal 102 causes the display unit 308 to display the error screen 1016.
[0327] In this embodiment, the second scan control sequence, the third scan control sequence, and the fourth scan control sequence are shown as methods for controlling an image forming device using authentication information obtained by two-step authentication, but the present invention is not limited to these.
[0328] As described above, by performing two-step authentication, the image forming device can only receive control instructions from the information terminal used by the user, which makes it possible to prevent spoofing. Furthermore, when scanning using two-step authentication, user operation and device processing can be performed simultaneously, making it possible to reduce the need for hands-free operation.
[0329] (Other Examples) The present invention can also be realized by supplying a program that realizes one or more functions of the above-described embodiments to a system or device via a network or a storage medium, and having one or more processors in the computer of the system or device read and execute the program.The present invention can also be realized by a circuit (e.g., ASIC) that realizes one or more functions. [Explanation of symbols]
[0330] 101 Image forming device 102 Information terminal 103 Cloud Server 104 Authentication Server 202 CPU 302 CPU 402 CPU 502 CPU
Claims
1. 1. An image processing system, comprising: an image processing device; an information terminal; The information terminal Accept user information from the user, Sending the user information to an authentication server; a first authentication process based on the user information is executed by the authentication server, and a code transmitted from the authentication server as a result of the first authentication process is received from the user; transmitting information used to cause the image processing device to execute a process of reading a document without waiting for reception of the code from the user; sending the code to the authentication server; a second authentication process based on the code is executed by the authentication server, and authentication information transmitted from the authentication server as a result of the second authentication process is transmitted to the image processing device; The image processing device includes: reading the original in response to receiving the information; an image processing system that transmits image data generated by scanning the document and the authentication information transmitted from the information terminal to an external device;
2. 2. The image processing system according to claim 1, wherein the image processing device transmits an HTTPS POST request to the external device, the HTTPS POST request including the authentication information as an HTTP header and the image data as a message body.
3. 3. The image processing system according to claim 1, wherein the external device is a device different from the information terminal.
4. 3. The image processing system according to claim 1, wherein the external device is the information terminal.
5. The image processing system according to claim 1 , wherein the external device is a cloud server.
6. the information terminal transmits the user information to the authentication server via the cloud server; The image processing system according to claim 5 , wherein the information terminal transmits the code to the authentication server via the cloud server.
7. 7. The image processing system according to claim 1, wherein the image processing device includes a printing unit.
8. an image processing device; and an information terminal, receiving user information from the user by the information terminal; transmitting the user information to an authentication server by the information terminal; a first authentication process based on the user information is executed by the authentication server, and a code transmitted from the authentication server as a result of the first authentication process is received by the information terminal from the user; transmitting information used to cause the image processing device to execute a process of reading a document by the information terminal without waiting for reception of the code from the user; transmitting the code to the authentication server by the information terminal; a second authentication process based on the code is executed by the authentication server, and authentication information transmitted from the authentication server as a result of the second authentication process is transmitted to the image processing device by the information terminal; In response to receiving the information, the image processing device reads the document; A control method for an image processing system, comprising the steps of: transmitting image data generated by reading the document and the authentication information transmitted from the information terminal to an external device;
9. 9. A program for causing a computer to execute the method for controlling an image processing system according to claim 8.
Citation Information
Patent Citations
Network device access control method and device, computer program, and computer readable storage medium
JP2004185629A
Information processing system, equipment, information processing method, and program
JP2014095971A
Server related to authentication and setting when scanning, image processing apparatus, service method, and image processing method
JP2015103917A
Server
JP2019003426A