Authentication device, authentication method, and program

The authentication device with a maintenance mode control unit and password verification system prevents unauthorized maintenance by restricting access and allowing authorized resets, ensuring proper device operation.

JP7854330B2Active Publication Date: 2026-05-01RISO KAGAKU CORP
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
RISO KAGAKU CORP
Filing Date
2022-04-11
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

Existing authentication systems for maintenance operations in devices like printing devices are vulnerable to password leakage, duplication, or misuse, allowing unauthorized individuals to perform maintenance, leading to functional decline or malfunction.

Method used

An authentication device with a maintenance mode control unit, authentication unit, and mode restriction unit that verifies passwords, restricts maintenance mode access, and allows password resets using IC chip devices, ensuring only authorized personnel can perform maintenance.

Benefits of technology

Prevents improper maintenance by restricting access and ensuring only knowledgeable personnel can execute maintenance operations, thereby maintaining device functionality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007854330000001
    Figure 0007854330000001
  • Figure 0007854330000002
    Figure 0007854330000002
  • Figure 0007854330000003
    Figure 0007854330000003
Patent Text Reader

Abstract

To provide an authentication apparatus, a storage device, an authentication method, and a program for suppressing inappropriate maintenance.SOLUTION: A printing apparatus 1, which is an example of an authentication apparatus, is provided with a maintenance mode control unit 51 that controls a maintenance mode, an authentication unit 52 that determines whether or not the maintenance mode can be performed based on an input password, and a mode restriction control unit 53 that restricts contents of the maintenance mode that can be performed by the maintenance mode control unit 51 based on a password determination status by the maintenance mode control unit 52.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an authentication device including a maintenance mode control unit, a storage device for storing authentication information, an authentication method, and a program.

Background Art

[0002] Conventionally, when inappropriate maintenance is performed on a maintenance target device such as a printing device, the device functions may not be fully exhibited, such as a decline in print quality, or the device may malfunction or experience operational problems. Therefore, a password for permitting execution of the maintenance mode is set to be changeable, and further, an authentication device has been proposed that can reset the password using a card-shaped IC chip device having an IC chip when a maintenance worker forgets the password (see, for example, Patent Document 1).

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] By the way, as in the above-described authentication device, since it is possible to set a password and reset the password using an IC chip device, it is possible to avoid a situation where a person without maintenance knowledge can perform maintenance arbitrarily.

[0005] However, risks such as leakage of the password, duplication or leakage of the IC chip device remain. Therefore, there is a risk that a person without maintenance knowledge may perform maintenance on the device, resulting in the device not being able to fully exhibit its functions or malfunctioning or experiencing operational problems.

[0006] The object of the present invention is to provide a printing apparatus, a storage device, an authentication method, and a program that can prevent improper maintenance from being performed. [Means for solving the problem]

[0007] In one embodiment, the authentication device includes a maintenance mode control unit that controls the maintenance mode, an authentication unit that determines whether the maintenance mode can be executed based on an entered password, and a mode restriction unit that restricts the content of the maintenance mode that can be executed by the maintenance mode control unit based on the password determination status by the authentication unit. [Effects of the Invention]

[0008] According to the above embodiment, it is possible to prevent improper maintenance from being performed. [Brief explanation of the drawing]

[0009] [Figure 1] This is a block diagram showing a printing apparatus in one embodiment. [Figure 2] This is a flowchart illustrating password changes and restrictions on the contents of maintenance mode in one embodiment. [Figure 3] This figure shows an example of a password input screen in one embodiment. [Figure 4] This figure shows an example of a maintenance mode screen in one embodiment. [Figure 5] This figure shows an example of a password change screen in one embodiment. [Figure 6] This is a flowchart illustrating password reset in one embodiment. [Figure 7] This is a flowchart illustrating the removal of restrictions on the contents of maintenance mode and the change of authentication information for password reset in one embodiment. [Modes for carrying out the invention]

[0010] Hereinafter, an authentication device, storage device, authentication method, and program according to one embodiment of the present invention will be described with reference to the drawings, with an example of the authentication device being a printing device 1 and an example of the storage device being a USB (Universal Serial Bus) dongle 103.

[0011] Figure 1 is a block diagram showing a printing apparatus 1 in one embodiment.

[0012] The printing device 1 shown in Figure 1 comprises a media supply unit 10, a transport unit 20, a printing unit 30, a media discharge unit 40, a control unit 50, a storage unit 60, an operation panel 70, and an interface unit 80. The printing device 1 is an example of an authentication device and determines whether or not the maintenance mode of the device to be maintained (printing device 1) can be executed.

[0013] The media supply unit 10 has a stacking platform on which media such as paper are stacked, and supplies the media stacked on this stacking platform into the printing device 1.

[0014] The transport unit 20 has, for example, rollers, belts, etc., and transports the medium inside the printing apparatus 1.

[0015] The printing unit 30 prints on the medium transported by the transport unit 20. The printing method of the printing unit 30 is not particularly limited, but examples include inkjet printing and stencil printing.

[0016] The media discharge unit 40 has a loading platform on which media are stacked and which is exposed to the outside of the printing device 1, and discharges the media that has been printed by the printing unit 30 onto the loading platform.

[0017] The control unit 50 has, for example, one or more processors (e.g., a CPU: Central Processing Unit) that function as an arithmetic processing unit for controlling the operations of each part of the printing apparatus 1. This processor reads and executes a predetermined program from, for example, the storage unit 60 or a storage medium (non-transitory computer-readable recording medium) that is detachable from the printing apparatus 1, thereby functioning as a maintenance mode control unit 51, an authentication unit 52, a mode restriction unit 53, and an authentication information acquisition unit 54.

[0018] The maintenance mode control unit 51 controls the maintenance mode of the printing apparatus 1. The maintenance mode control unit 51 executes the maintenance mode when the execution of the maintenance mode is permitted by the authentication unit 52 described later. This maintenance mode is, for example, a mode for performing maintenance including setting changes of each part such as changing the conveyance settings of the conveyance unit 20 and the printing settings of the printing unit 30, cleaning operations of each part, operation confirmation of each part, and confirmation of the count numbers of each part such as the number of printed sheets and the number of consumable usage times of the printing unit 30.

[0019] The authentication unit 52 determines whether the execution of the maintenance mode by the maintenance mode control unit 51 is possible based on the input password. For example, the password includes a predetermined number of digits of numbers, characters, symbols, etc., and is input by a maintenance staff via the input unit 72 or the interface unit 80 described later.

[0020] For example, the authentication unit 52 checks whether the input password input by the maintenance staff using the touch panel or numeric keypad of the input unit 72 matches the current password stored in the storage unit 60, and when these passwords match, it may permit the execution of the maintenance mode by the maintenance mode control unit 51. In addition, when the password matches and the maintenance mode is executed, if a password change is requested, the authentication unit 52 permits the password change and stores the new password input to the input unit 72 in the storage unit 60.

[0021] As will be explained in more detail later, the authentication unit 52 permits password reset if the authentication information obtained from the second IC chip device 102 by the authentication information acquisition unit 54 includes password reset authentication information (authentication key A), and stores the new password entered in the input unit 72 in the storage unit 60. Password reset is performed, for example, when a maintenance worker forgets the maintenance password. That is, when resetting the password, it is not necessary to enter the latest password stored in the storage unit 60; for example, the password can be changed to a new password after initializing it. The authentication key, like the maintenance password, may include, for example, numbers, letters, symbols, etc., for a predetermined number of digits.

[0022] The mode restriction unit 53 restricts the content of the maintenance mode that can be executed by the maintenance mode control unit 51 based on the password determination status by the authentication unit 52. For example, the mode restriction unit 53 restricts the content of the maintenance mode that can be executed by the maintenance mode control unit 51 to a first restriction mode and a second restriction mode that has more restrictions than the first restriction mode. In addition, the mode restriction unit 53 removes the restrictions on the content of the maintenance mode if the authentication information obtained from the USB dongle 103 by the authentication information acquisition unit 54 includes authentication information for removing restrictions on the content of the maintenance mode. Furthermore, if the authentication information obtained from the USB dongle 103 by the authentication information acquisition unit 54 includes authentication information for removing restrictions on the content of the maintenance mode, the authentication unit 52 permits a change in the password reset authentication information, for example, from authentication key A to authentication key B.

[0023] For example, the first constraint mode is a maintenance mode in which it is not possible to change the settings of each part, such as changing the transport settings of the transport unit 20 or changing the print settings of the print unit 30. The second constraint mode is a maintenance mode in which it is not possible to change the settings of each part or check the operation of each part as described above, and only cleaning operations of each part and counts such as the number of printed pages and the number of times consumables are used in the print unit 30 can be performed. However, the first and second constraint modes are not limited to the above example; for example, the first constraint mode may be a maintenance mode in which it is not possible to change some of the settings of each part, and the second constraint mode may be a maintenance mode in which it is not possible to change some or all of the settings of each part, which is more than in the first constraint mode.

[0024] The password verification status by the authentication unit 52 includes, for example, the same password being used, the incorrect password being entered, and the password being changed.

[0025] The same password usage status refers to, for example, the period during which the same password has been used, or the number of times the same password has been entered. The mode limiting unit 53 restricts the contents of the maintenance mode if the same password has been used for a specified period or for a specified number of times, or if both the period and the number of times criteria are met.

[0026] Furthermore, the password error status is, for example, the number of times an incorrect password was entered, or the percentage of incorrect passwords entered (the percentage of incorrect passwords entered relative to the number of times a password was entered). The mode limiting unit 53 restricts the contents of the maintenance mode if the number of times an incorrect password was entered exceeds a specified number of times, if the percentage of incorrect passwords entered exceeds a specified percentage, or if both the number of times and the percentage criteria are met.

[0027] Furthermore, the password change status, which indicates that a password has been changed, is, for example, the number of times the password has been changed, or the average time between password changes (the average time until the password is changed once within a specified period). The mode limiting unit 53 restricts the contents of the maintenance mode if the number of password changes exceeds the specified number of changes, if the average time between password changes is shorter than the specified period, or if both the specified number of changes and the average time are met.

[0028] Furthermore, the mode limiting unit 53 may limit the content of the maintenance mode that can be executed by the maintenance mode control unit 51 based on the conditions under which the restrictions on the content of the maintenance mode by the mode limiting unit 53 are lifted. The conditions under which the restrictions on the content of the maintenance mode by the mode limiting unit 53 are lifted include, for example, the number of times the restrictions have been lifted, or the average period over which restrictions are lifted (the average period until a restriction is lifted once within a specified period). The mode limiting unit 53 restricts the content of the maintenance mode if the number of times the restrictions are lifted is equal to or greater than the specified number of times the restrictions are lifted, if the average period over which restrictions are lifted is shorter than the specified period, or if both the number of times the restrictions are lifted and the average period are met, because there is a suspicion of a malfunction in the printing device 1 or that unnatural operation is being performed, and there is a possibility that maintenance is being performed by an inappropriate person.

[0029] The authentication information acquisition unit 54 acquires authentication information from the second IC chip device 102 and the USB dongle 103, which are examples of storage media (memory devices). This authentication information includes, for example, password reset authentication information (e.g., authentication key A) stored in the second IC chip device 102, and restriction removal authentication information stored in the USB dongle 103.

[0030] The storage unit 60 includes, for example, a ROM (Read Only Memory), which is a read-only semiconductor memory in which a predetermined control program is pre-recorded, a RAM (Random Access Memory), which is a semiconductor memory that can be written to and read at any time and used as a working memory area as needed when the processor executes various control programs, and a hard disk drive. When the printing device 1 is shipped, the storage unit 60 stores an initial password as a maintenance password. After the maintenance password is changed from the initial password, the storage unit 60 stores the current (latest) maintenance password and the initial password. The storage unit 60 also stores authentication information for password reset (authentication key A) and authentication information for removing restrictions.

[0031] The control panel 70 has a display unit 71 which is a display that shows various information, and an input unit 72 which accepts input of various information from the user (for example, a general user, a maintenance worker, etc.). If the display unit 71 is a touch panel, the display unit 71 also serves as the input unit 72. The maintenance worker may be a person selected from among the general users, or a maintenance professional.

[0032] The interface unit 80 exchanges various types of information with various devices. For example, the interface unit 80 functions as a reader / writer device that reads information from the first IC chip device 101, the second IC chip device 102, and the USB dongle 103, and writes information to them. The authentication information for password reset of the second IC chip device 102 and the authentication information for unlocking restrictions of the USB dongle 103, which are read by the interface unit 80, are acquired by the authentication information acquisition unit 54 as described above. The interface unit 80 also receives print jobs from user terminals connected wirelessly or via wired connection over the network.

[0033] The first IC chip device 101 and the second IC chip device 102 are selectively and detachably mounted in predetermined mounting locations on the printing device 1. For example, the first IC chip device 101 and the second IC chip device 102 are cards that have IC chips for storing various information and are inserted into the aforementioned mounting locations.

[0034] The first IC chip device 101 is installed in the printing device 1 during normal use, such as printing operations. The first IC chip device 101 stores information such as the serial number of the printing device 1 to which the first IC chip device 101 is installed, destination information of the printing device 1, information indicating the model of the printing device 1, and information indicating the type of IC chip device. Here, the information indicating the type of IC chip device indicates whether it is the first IC chip device 101 or the second IC chip device 102.

[0035] The second IC chip device 102 is installed in the printer 1 after the first IC chip device 101 is removed when resetting the maintenance password. The second IC chip device 102 stores information such as password reset authentication information, information indicating the type of IC chip device, and the model of the printer 1 that the second IC chip device 102 can be used with. The second IC chip device 102 can be used in common with multiple printers 1.

[0036] The second IC chip device 102 has a set number of uses as a condition for use. The second IC chip device 102 stores the number of uses it has had and the number of uses to date. The number of uses of the second IC chip device 102 is the number of times the maintenance password has been reset while the second IC chip device 102 is installed in the printing device 1.

[0037] The USB dongle 103 stores information such as authentication information for removing the restrictions on the contents of maintenance mode, authentication information for resetting the newly set password (e.g., authentication key B), information indicating the type of USB dongle (memory), and the model of the printer 1 that the USB dongle 103 can be used with.

[0038] Furthermore, instead of the second IC chip device 102, other storage media such as a USB dongle may be used as the storage medium (device) for storing authentication information for password reset, and instead of the USB dongle 103, other storage media such as an IC chip device may be used as the storage medium (device) for storing authentication information for unlocking restrictions.

[0039] Furthermore, in the above description, the printing device 1 is both an example of a device to be maintained and an example of an authentication device. That is, the authentication device and the device to be maintained are the same device. However, the authentication device may be a device other than the device to be maintained, for example, a device that determines whether or not the maintenance mode of the device to be maintained can be executed. For example, the authentication device may be a dedicated control device that controls the device to be maintained (for example, a print control device that controls the printing device 1, which is the device to be maintained), or it may be a user terminal such as a smartphone, tablet, or personal computer that controls the device to be maintained, and is not particularly limited.

[0040] Furthermore, the maintenance mode control unit 51, which controls the maintenance mode of the device under maintenance, may be provided on the device under maintenance, or it may be provided on an authentication device located separately from the device under maintenance.

[0041] Furthermore, the device to be maintained (authentication device) is not limited to the printing device 1, but may also be a post-processing device that processes the medium printed by the printing device 1, or a scanner that reads the image data printed by the printing device 1, or other printing-related devices. Moreover, the device to be maintained (authentication device) is not limited to printing-related devices, but may also be other devices such as home appliances or automobiles.

[0042] Next, we will explain the process of changing your password (a normal change, not a password reset due to forgetting your password) and the limitations of the maintenance mode, referring to the flowchart in Figure 2.

[0043] The flowchart in Figure 2 is performed by the control unit 50 when the first IC chip device 101 is installed in the printer 1 and the printer 1 is powered on. For example, the first IC chip device 101 is installed in the printer 1 while the printer 1 is powered off, and then the printer 1 is powered on. At the point when the power is turned on, the printer 1 is in print mode, which is a mode in which printing operations are possible.

[0044] First, the authentication unit 52 repeatedly determines whether a request to transition to maintenance mode has been made until such a request is made (step S1). This transition request is made by a predetermined operation by a maintenance worker, such as pressing a predetermined number of keys on the input unit 72.

[0045] When a migration request is made (Step S1: YES), the authentication unit 52 displays the password input screen 71a shown in Figure 3 on the display unit 71 (Step S2). The authentication unit 52 also retrieves the maintenance password entered by the maintenance worker from the input unit 72 and determines whether it matches the latest password stored in the storage unit 60 (Step S3). If the passwords do not match (Step S3: NO), the authentication unit 52 may notify the maintenance worker of this fact, for example, by displaying it on the display unit 71. After that, the determination process in Step S9, which will be described later, is performed.

[0046] If the password matches (Step S3: YES), the authentication unit 52 permits the execution of maintenance mode, and the maintenance mode control unit 51 transitions to maintenance mode and displays the maintenance mode screen 71b shown in Figure 4 on the display unit 71 (Step S4). Subsequently, the maintenance mode control unit 51 executes the maintenance items selected by the maintenance worker ("No. 11...", "No. 12...", "No. 13...", etc.) on the maintenance mode screen 71b.

[0047] Next, the authentication unit 52 determines whether the password change function has been selected, for example, by pressing the password change button on the maintenance mode screen 71b (step S5). If the password change function has not been selected (step S5: NO), the determination process in step S8, described later, is performed. If a password change button is provided, it is advisable not to display the name of the function, but rather a symbol or something unfamiliar to non-maintenance personnel, so that this password change button is not recognized by anyone other than maintenance personnel.

[0048] When the password change function is selected (Step S5: YES), the authentication unit 52 displays the password change screen 71c shown in Figure 5 on the display unit 71 (Step S6). The authentication unit 52 also retrieves the changed password entered by the maintenance worker from the input unit 72 and updates (changes) the latest password stored in the storage unit 60 (Step S7).

[0049] Next, the maintenance mode control unit 51 determines whether an operation to request the termination of maintenance mode has been performed, such as pressing the termination button on the maintenance mode screen 71b shown in Figure 4 (step S8). If no operation to request the termination of maintenance mode has been performed (step S8: NO), the process returns to determining whether the password change function described above has been selected (step S5).

[0050] On the other hand, if an operation to request termination of maintenance mode is performed (step S8: YES), the mode limiting unit 53 determines whether the above-mentioned password determination status, such as the same password usage status where the same password is being used, the incorrect password status where the entered password was incorrect, or the password change status where the password has been changed, satisfies the conditions for limiting the content of the maintenance mode that can be executed by the maintenance mode control unit 51 (step S9).

[0051] If the password determination status satisfies the conditions for restricting the contents of maintenance mode (step S9: YES), the mode restriction unit 53 notifies the maintenance personnel, for example, by displaying on the display unit 71, and restricts the contents of the maintenance mode from the next time onward (step S10), and the process shown in Figure 2 ends. If the password determination status does not satisfy the conditions for restricting the contents of maintenance mode (step S9: NO), the process shown in Figure 2 ends.

[0052] The process of determining whether the conditions for restricting the contents of maintenance mode are met (step S9) and the process of restricting the contents of maintenance mode (step S10) may be performed at different times, for example, after the process of determining whether the password matches (step S3) and before the display process of the maintenance mode screen 71b (step S4). If performed at this timing, it becomes possible to restrict the contents of maintenance mode immediately after the password matching determination.

[0053] Next, we will explain how to reset your password, referring to the flowchart in Figure 6.

[0054] The flowchart in Figure 6 is performed by the control unit 50 when, for example, a maintenance worker forgets the maintenance password, the second IC chip device 102 is installed in the printer 1 and the printer 1 is powered on. For example, the second IC chip device 102 is installed in the printer 1 while the printer 1 is powered off, and then the printer 1 is powered on. At this stage, the authentication information for password reset stored in the storage unit 60 is assumed to be authentication key A.

[0055] First, the authentication unit 52 determines whether the second IC chip device 102 has been installed in the printing device 1 based on whether the authentication information acquisition unit 54 has acquired authentication information and other information (step S21). If the second IC chip device 102 has not been installed in the printing device 1 (step S21: NO), the process shown in Figure 6 ends.

[0056] If the second IC chip device 102 is installed in the printing device 1 (step S21: YES), the authentication unit 52 determines whether the second IC chip device 102 satisfies the conditions for password reset (step S22). For example, the authentication unit 52 determines that the second IC chip device 102 satisfies the conditions for password reset if the authentication information obtained from the second IC chip device 102 by the authentication information acquisition unit 54 includes the same password reset authentication information (authentication key A) as that stored in the storage unit 60, and the number of times the second IC chip device 102 can be used is greater than the number of times it has been used to date. The conditions for password reset of the second IC chip device 102 can be changed as appropriate, for example, by using other criteria such as an expiration date instead of the number of times it can be used, or by only requiring that the authentication information obtained from the second IC chip device 102 includes password reset authentication information.

[0057] If the second IC chip device 102 does not meet the conditions for password reset (step S22: NO), the process shown in Figure 6 is terminated.

[0058] If the second IC chip device 102 meets the conditions for password reset (step S22: YES), the authentication unit 52 changes the latest password stored in the storage unit 60 to the initial password and displays the password input screen 71a shown in Figure 5 on the display unit 71 (step S23). The authentication unit 52 also obtains the initial maintenance password entered by the maintenance worker from the input unit 72 and determines whether it matches the initial password stored in the storage unit 60 (step S24). If the initial passwords do not match (step S24: NO), the process shown in Figure 6 ends. Note that since the maintenance worker has the initial password stored in advance, any legitimate maintenance worker can enter the initial password. However, the initial password setting process (step S23) and the initial password match determination process (step S24) may be omitted.

[0059] If the initial password matches (step S24: YES), the authentication unit 52 permits the execution of maintenance mode, and the maintenance mode control unit 51 transitions to maintenance mode and displays the maintenance mode screen 71b shown in Figure 4 on the display unit 71 (step S25). Next, the authentication unit 52 determines whether the password change function has been selected, for example, by pressing the password change button on the maintenance mode screen 71b (step S26). If the password change function has not been selected (step S26: NO), the process shown in Figure 6 ends. Note that if the password change button is located in a different part of the maintenance mode screen 71b, the execution of maintenance mode (step S25) can be omitted.

[0060] When the password change function is selected (step S26: YES), the authentication unit 52 displays the password change screen 71c shown in Figure 5 on the display unit 71 (step S27). The authentication unit 52 also retrieves the changed password entered by the maintenance worker from the input unit 72 and resets (changes) the latest password stored in the storage unit 60 (step S28).

[0061] Subsequently, the authentication unit 52 updates the usage count stored in the second IC chip device 102 by increasing it by one (step S29). Then, the process shown in Figure 6 is completed. After the process shown in Figure 6 is completed, the maintenance worker turns off the power to the printer 1 and removes the second IC chip device 102 from the printer 1. Then, the maintenance worker installs the first IC chip device 101 into the printer 1 and turns on the power to the printer 1. This makes the printer 1 capable of executing the printing mode.

[0062] Next, we will explain how to remove the restrictions on the contents of maintenance mode and how to change the authentication information for password reset (authentication key A), referring to the flowchart in Figure 7.

[0063] The flowchart in Figure 7 is performed by the control unit 50 when the contents of the maintenance mode that can be executed by the maintenance mode control unit 51 are limited (step S10 in Figure 2), with the USB dongle 103 attached to the printer 1, as described above. At this stage, the authentication information for password reset stored in the storage unit 60 is assumed to be authentication key A, as in the flowchart in Figure 6.

[0064] First, the authentication unit 52 determines whether the USB dongle 103 is attached to the printer 1, for example, based on whether authentication information or other information has been acquired by the authentication information acquisition unit 54 (step S31). The authentication unit 52 may also determine whether the USB dongle 103 satisfies the usage conditions based on whether the USB dongle 103 contains the same restriction removal authentication information as stored in the storage unit 60.

[0065] If the USB dongle 103 is installed in the printer 1 (step S31: YES), the authentication unit 52, for example, displays a screen on the display unit 71 for selecting whether to change the password reset authentication information (authentication key A), and then determines whether the authentication key change function has been selected (step S32). If the authentication key change function is not selected (step S32: NO), the process shown in Figure 7 ends. In this case, the process of releasing the restrictions on the contents of the maintenance mode (step S34), which will be described later, will not be performed, but the process shown in Figure 7 may end after the process of releasing the restrictions on the contents of the maintenance mode (step S34) has been performed.

[0066] If the authentication key change function is selected (step S32: YES), the authentication unit 52 changes the password reset authentication information stored in the storage unit 60 from authentication key A to, for example, authentication key B stored in the USB dongle 103 (step S33). As a result, password reset using the second IC chip device 102 that stores authentication key A will no longer be possible.

[0067] Next, the mode restriction unit 53 releases the restriction on the contents of the maintenance mode that can be executed by the maintenance mode control unit 51 (step S34). Then, the mode restriction unit 53 resets the password change status by the authentication unit 52 stored in the storage unit 60 (step S35). Note that this reset process of the password change status by the authentication unit 52 (step S35) may be performed after the restriction on the contents of the maintenance mode (step S10) and before the restriction release (step 34), as shown in Figure 2, rather than after the release of the restriction on the contents of the maintenance mode (step 34).

[0068] Next, the authentication unit 52 displays the password change screen 71c shown in Figure 5 on the display unit 71 (step S36). The authentication unit 52 also retrieves the changed password entered by the maintenance worker from the input unit 72 and resets (changes) the latest password stored in the storage unit 60 (step S37).

[0069] Then, the authentication unit 52 deletes (or disables) at least the authentication information for unlocking restrictions from the information stored in the USB dongle 103 (step S38). The authentication unit 52 may also delete the authentication key B (authentication information for resetting a new password) stored in the USB dongle 103. Although the deletion of the authentication information for unlocking restrictions is an optional process, it is desirable to delete it to prevent misuse such as unauthorized persons using the authentication information to unlock the maintenance mode restrictions or duplicating the authentication information after the USB dongle 103 is lost. After that, the process shown in Figure 7 may be terminated, but if the maintenance mode restriction process in Figure 2 (step S10) and the maintenance mode restriction removal process in Figure 9 (step S354 in Figure 7) are repeated, there is a possibility of a malfunction of the printer 1. For this reason, the mode restriction unit 53 may, based on the unlocking status of the maintenance mode content by the mode restriction unit 53, restrict the contents of the maintenance mode that can be executed by the maintenance mode control unit 51 again.

[0070] First, the mode restriction unit 53 determines whether the restriction release status is abnormal (step S39). As described above, this restriction release status is, for example, the number of times the restriction has been released, or the average period during which the restriction is released (the average period until the restriction is released once in a specified period). The mode restriction unit 53 may determine that the status is abnormal if the number of restriction releases is equal to or greater than the specified number of restriction releases, if the average period during which the restriction is released is shorter than the specified period, or if both the criteria for the number of restriction releases and the average period are met.

[0071] If the restriction release status is normal (step S39: NO), the process shown in Figure 7 ends. On the other hand, if the restriction release status is abnormal (step S39: YES), the mode restriction unit 53 restricts the contents of the maintenance mode again (step S40). The mode restriction unit 53 (control unit 50) also controls the interface unit 80 to notify the maintenance company or the sales company of the printing device 1 of the abnormality in the restriction release status (step S41). Then, the process shown in Figure 7 ends.

[0072] In the embodiment described above, the printing device 1, which is an example of an authentication device, includes a maintenance mode control unit 51 that controls the maintenance mode, an authentication unit 52 that determines whether or not the maintenance mode can be executed based on the entered password, and a mode restriction unit 53 that restricts the content of the maintenance mode that can be executed by the maintenance mode control unit 51 based on the password determination status by the authentication unit 52.

[0073] Furthermore, from another perspective, the authentication method is an authentication method performed by a computer (for example, the printing device 1 or the control unit 50 of the printing device 1), and includes a step of controlling the maintenance mode (for example, step S4 in Figure 2), a step of determining whether or not the maintenance mode can be executed based on the entered password (step S9), and a step of restricting the content of the executable maintenance mode based on the password determination status (step S10).

[0074] From another perspective, the program causes the computer (for example, the printer 1 or the control unit 50 of the printer 1) to execute the following functions: a function to control the maintenance mode (for example, step S4 in Figure 2), a function to determine whether or not the maintenance mode can be executed based on the entered password (step S9), and a function to restrict the content of the executable maintenance mode based on the password determination status (step S10).

[0075] These authentication devices (printing device 1), authentication methods, and programs can restrict the contents of the maintenance mode in cases where maintenance may be performed by someone without maintenance knowledge, such as when the same password is used repeatedly, when the entered password is often incorrect, or when the password is changed frequently. Therefore, according to this embodiment, it is possible to suppress inappropriate maintenance.

[0076] Furthermore, in this embodiment, the printing device 1 includes an authentication information acquisition unit 54 that acquires authentication information from a USB dongle 103, which is an example of a storage medium (storage device). The mode restriction unit 53 releases the restrictions on the contents of the maintenance mode when the authentication information acquired by the authentication information acquisition unit 54 includes authentication information for releasing restrictions.

[0077] From another perspective, the USB dongle 103, which is an example of a storage device, stores authentication information acquired by the authentication information acquisition unit 54 of the printing device 1, which is an example of an authentication device. The printing device 1 includes a maintenance mode control unit 51 that controls the maintenance mode, an authentication unit 52 that determines whether or not the maintenance mode can be executed based on the entered password, a mode restriction unit 53 that restricts the contents of the maintenance mode that can be executed by the maintenance mode control unit 51 based on the password determination status by the authentication unit 52, and an authentication information acquisition unit 54 that acquires authentication information. The authentication information stored in the USB dongle 103 includes authentication information for removing restrictions to remove the restrictions on the contents of the maintenance mode by the mode restriction unit 53.

[0078] With these authentication devices (printing device 1) and storage devices (USB dongle 103), by limiting the recipients of the USB dongle 103 that stores the authentication information for removing restrictions, it becomes impossible for someone without maintenance knowledge to arbitrarily remove the restrictions on the contents of maintenance mode. This further deters inappropriate maintenance from being performed.

[0079] Furthermore, in this embodiment, the authentication unit 52 permits password reset if the authentication information obtained by the authentication information acquisition unit 54 includes authentication information for password reset (for example, authentication key A stored in the second IC chip device 102), and permits changing the authentication information for password reset if the authentication information obtained by the authentication information acquisition unit 54 includes authentication information for removing restrictions (for example, stored in the USB dongle 103).

[0080] This allows maintenance personnel to reset the maintenance password using the second IC chip device 102 if they forget it. Furthermore, if the contents of the maintenance mode are restricted, there is a possibility that someone without maintenance knowledge may be performing maintenance, as mentioned above. Therefore, by allowing changes to the password reset authentication information when the restrictions on the contents of the maintenance mode are lifted using the USB dongle 103 that stores the authentication information for lifting restrictions, it is possible to prevent the second IC chip device 102 from being lost or misused. Thus, inappropriate maintenance can be further deterred.

[0081] Furthermore, in this embodiment, the password determination status is the same password usage status, where the same password is being used. The mode restriction unit 53 restricts the content of the maintenance mode that can be executed by the maintenance mode control unit 51 based on the same password usage status. For example, the mode restriction unit 53 restricts the content of the executable maintenance mode to a first constraint mode and a second constraint mode that has more restrictions than the first constraint mode, based on the password determination status by the authentication unit 52. The mode restriction unit 53 then restricts the content of the maintenance mode that can be executed by the maintenance mode control unit 51 to the first constraint mode based on the same password usage status.

[0082] This allows for restricting the contents of the maintenance mode when there is a possibility that someone without maintenance knowledge is performing maintenance, such as when the same password is continuously being used. Therefore, it is possible to prevent inappropriate maintenance from being performed. Furthermore, when the same password is continuously being used, the possibility of someone without maintenance knowledge performing maintenance is relatively low, so by partially restricting the contents of the maintenance mode to the first constraint mode, inappropriate maintenance can be appropriately prevented.

[0083] Furthermore, in this embodiment, the password determination status is a password error status where the entered password is incorrect, and the mode restriction unit 53 restricts the content of the maintenance mode that can be executed by the maintenance mode control unit 51 based on the password error status. For example, the mode restriction unit 53 restricts the content of the executable maintenance mode to a first constraint mode and a second constraint mode that has more restrictions than the first constraint mode, based on the password determination status by the authentication unit 52. The mode restriction unit 53 restricts the content of the maintenance mode that can be executed by the maintenance mode control unit 51 to the second constraint mode based on the password error status.

[0084] This allows for restricting the contents of the maintenance mode when maintenance is being performed by someone without maintenance knowledge, such as when incorrect passwords are frequently entered. Therefore, it is possible to prevent inappropriate maintenance from being performed. In particular, when incorrect passwords are frequently entered, the possibility that maintenance is being performed by someone without maintenance knowledge is relatively high, so by severely restricting the contents of the maintenance mode to the second constraint mode, inappropriate maintenance can be appropriately prevented.

[0085] Furthermore, in this embodiment, the password determination status is the password change status, where the password has been changed, and the mode restriction unit 53 restricts the content of the maintenance mode that can be executed by the maintenance mode control unit 51 based on the password change status. For example, the mode restriction unit 53 restricts the content of the executable maintenance mode to a first constraint mode and a second constraint mode that has more restrictions than the first constraint mode, based on the password determination status by the authentication unit 52. The mode restriction unit 53 restricts the content of the maintenance mode that can be executed by the maintenance mode control unit 51 to the first constraint mode based on the password change status.

[0086] This allows for restricting the contents of the maintenance mode when there is a possibility that maintenance is being performed by someone without maintenance knowledge, such as when passwords are being changed frequently. Therefore, it is possible to suppress inappropriate maintenance. In the case of frequent password changes, the possibility of maintenance being performed by someone without maintenance knowledge is relatively low, so by partially restricting the contents of the maintenance mode to the first constraint mode, inappropriate maintenance can be appropriately suppressed.

[0087] Furthermore, in this embodiment, the mode limiting unit 53 restricts the content of the maintenance mode that can be executed by the maintenance mode control unit 51 based on the status of the restriction release, in which the restriction on the content of the maintenance mode by the mode limiting unit 53 is released.

[0088] This allows the contents of the maintenance mode to be restricted if there is suspicion of a malfunction in the printer 1 or if unusual operation is being performed, such as when the restrictions on the contents of the maintenance mode are frequently lifted. Therefore, it is possible to prevent inappropriate maintenance from being performed.

[0089] It should be noted that the present invention is not limited to the embodiments described above, and the components can be modified and implemented in practice without departing from the spirit of the invention. Furthermore, various inventions can be formed by appropriately combining the multiple components disclosed in the embodiments described above. For example, all the components shown in the embodiments may be combined as appropriate. It goes without saying that various modifications and applications are possible without departing from the spirit of the invention. The invention described in the original claims of this application is listed below.

[0090] [Note 1] A maintenance mode control unit that controls the maintenance mode, An authentication unit that determines whether the aforementioned maintenance mode can be executed based on the entered password, A mode restriction unit restricts the content of the maintenance mode that can be executed by the maintenance mode control unit based on the password determination status by the authentication unit. An authentication device characterized by being equipped with the following features.

[0091] [Note 2] It further includes an authentication information acquisition unit that acquires authentication information from a storage medium, The mode restriction unit releases the restriction on the contents of the maintenance mode if the authentication information acquired by the authentication information acquisition unit includes authentication information for releasing the restriction. The authentication device described in Appendix 1, characterized by the features described herein.

[0092] [Note 3] The authentication unit permits password reset if the authentication information obtained by the authentication information acquisition unit includes password reset authentication information, and permits changes to the password reset authentication information if the authentication information obtained by the authentication information acquisition unit includes restriction removal authentication information. The authentication device described in Appendix 2, characterized by the features described herein.

[0093] [Note 4] The aforementioned determination status of the password is the same password usage status, where the same password is being used. The mode restriction unit restricts the content of the maintenance mode that can be executed by the maintenance mode control unit based on the usage status of the same password. The authentication device described in Appendix 1, characterized by the features described herein.

[0094] [Note 5] The aforementioned password determination status is a password error status where the entered password was incorrect. The mode restriction unit restricts the content of the maintenance mode that can be executed by the maintenance mode control unit based on the password error status. The authentication device described in Appendix 1, characterized by the features described herein.

[0095] [Note 6] The mode limiting unit restricts the content of the maintenance mode that can be executed by the maintenance mode control unit based on the release status of the restriction on the content of the maintenance mode by the mode limiting unit. The authentication device described in Appendix 2, characterized by the features described herein.

[0096] [Note 7] A storage device for storing authentication information acquired by the authentication information acquisition unit of an authentication device comprising: a maintenance mode control unit for controlling a maintenance mode; an authentication unit for determining whether the maintenance mode can be executed based on an entered password; a mode restriction unit for restricting the content of the maintenance mode that can be executed by the maintenance mode control unit based on the password determination status by the authentication unit; and an authentication information acquisition unit for acquiring authentication information, wherein the authentication device stores the authentication information acquired by the authentication information acquisition unit, The authentication information stored in the storage device includes authentication information for releasing restrictions on the contents of the maintenance mode by the mode limiting unit. A storage device characterized by the following features.

[0097] [Note 8] A computer-based authentication method, The process of controlling the maintenance mode, The process of determining whether the aforementioned maintenance mode can be executed based on the entered password, A step of restricting the contents of the maintenance mode that can be executed based on the password determination status. An authentication method characterized by including [something].

[0098] [Note 9] Functions to control maintenance mode, A function to determine whether the aforementioned maintenance mode can be executed based on the entered password, A function to restrict the contents of the maintenance mode that can be executed based on the password determination status. A program characterized by causing a computer to execute something. [Explanation of Symbols]

[0099] 1 Printing device 10 Media supply section 20 Conveying section 30 Printing Department 40 Media discharge section 50 Control Unit 51 Maintenance Mode Control Unit 52 Certification Department 53 Mode Limitation Section 54 Authentication Information Acquisition Section 60 Storage section 70 Control Panel 71 Display section 71a Password entry screen 71b Maintenance Mode Screen 71c Password Change Screen 72 Input section 80 Interface section 101 First IC Chip Device 102 Second IC Chip Device 103 USB Dongles

Claims

1. A maintenance mode control unit that controls the maintenance mode, An authentication unit that determines whether the aforementioned maintenance mode can be executed based on the entered password, A mode restriction unit restricts the content of the maintenance mode that can be executed by the maintenance mode control unit based on the password determination status by the authentication unit, It includes an authentication information acquisition unit that acquires authentication information from a storage medium, The mode restriction unit releases the restriction on the contents of the maintenance mode when the authentication information acquired by the authentication information acquisition unit includes authentication information for releasing the restriction. The authentication unit permits password reset if the authentication information obtained by the authentication information acquisition unit includes password reset authentication information, and permits changes to the password reset authentication information if the authentication information obtained by the authentication information acquisition unit includes restriction removal authentication information. An authentication device characterized by the following features.

2. A maintenance mode control unit for controlling the maintenance mode, An authentication unit that determines whether the aforementioned maintenance mode can be executed based on the entered password, The system includes a mode restriction unit that restricts the content of the maintenance mode that can be executed by the maintenance mode control unit based on the password determination status by the authentication unit, The aforementioned determination status of the password is the same password usage status, where the same password is being used. The mode restriction unit restricts the content of the maintenance mode that can be executed by the maintenance mode control unit based on the usage status of the same password. An authentication device characterized by the following features.

3. The aforementioned password determination status is a password error status where the entered password was incorrect. The mode restriction unit restricts the content of the maintenance mode that can be executed by the maintenance mode control unit based on the password error status. The authentication device according to claim 1, characterized in that it is a feature of the present invention.

4. The mode limiting unit restricts the content of the maintenance mode that can be executed by the maintenance mode control unit based on the release status of the restriction on the content of the maintenance mode by the mode limiting unit. The authentication device according to claim 1, characterized in that it is a feature of the present invention.

5. A computer-based authentication method, The process of controlling the maintenance mode, The process of determining whether the aforementioned maintenance mode can be executed based on the entered password, A step of restricting the contents of the maintenance mode that can be executed based on the password determination status, This includes the step of obtaining authentication information from a storage medium, In the step of restricting the contents of the maintenance mode, if the acquired authentication information includes authentication information for removing the restriction, the restriction on the contents of the maintenance mode is removed. In the step of determining whether the maintenance mode can be executed, if the acquired authentication information includes authentication information for password reset, the password reset is permitted, and if the acquired authentication information includes authentication information for removing restrictions, the password reset authentication information is permitted to be changed. Authentication method characterized by the following features.

6. A computer-based authentication method, The process of controlling the maintenance mode, The process of determining whether the aforementioned maintenance mode can be executed based on the entered password, The process includes a step of restricting the contents of the maintenance mode that can be executed based on the password determination status, The aforementioned determination status of the password is the same password usage status, where the same password is being used. In the step of restricting the contents of the maintenance mode, the contents of the maintenance mode that can be executed are restricted based on the usage status of the same password. Authentication method characterized by the following features.

7. Functions to control maintenance mode, A function to determine whether the aforementioned maintenance mode can be executed based on the entered password, A function to restrict the contents of the maintenance mode that can be executed based on the password determination status, A function to obtain authentication information from a storage medium and A program that causes a computer to execute, The function that restricts the contents of the maintenance mode removes the restriction on the contents of the maintenance mode when the acquired authentication information includes authentication information for removing the restriction. The function that determines whether the maintenance mode can be executed allows the password to be reset if the acquired authentication information includes authentication information for password reset, and allows the password reset authentication information to be changed if the acquired authentication information includes authentication information for removing restrictions. A program characterized by the following features.

8. A function to control the maintenance mode, A function to determine whether the aforementioned maintenance mode can be executed based on the entered password, A function to restrict the contents of the maintenance mode that can be executed based on the password determination status, A program that causes a computer to execute, The aforementioned determination status of the password is the same password usage status, where the same password is being used. The function that restricts the contents of the maintenance mode restricts the contents of the maintenance mode that can be executed based on the usage status of the same password. A program characterized by the following features.

Citation Information

Patent Citations

  • Facsimile equipment

    JP1999284777A

  • Image forming system

    JP2010258770A

  • Installation package generation program of printer driver and utilization method of printer driver

    JP2017156980A

  • Authentication apparatus

    JP2019012297A

  • Controlling Maintenance of a Fuel Dispenser

    US20190127209A1