File delivery system, file delivery method, and program

The file provision system simplifies scanner sharing by using a scanner's serial number for web access authentication and one-time passwords, addressing account management and unauthorized access issues.

JP7857121B2Active Publication Date: 2026-05-12PFU LTD
View PDF 7 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
PFU LTD
Filing Date
2022-03-14
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

Existing systems for sharing file generation devices, such as scanners, face challenges with cumbersome account management and unauthorized access due to the limitations of web applications and the need for driver software installation.

Method used

A file provision system that utilizes a scanner's serial number for web access authentication, generates a one-time password when the user terminal is on the same network, and shares data files only after successful authentication, eliminating the need for account registration and driver software.

Benefits of technology

Enables secure and simple sharing of scanners by preventing unauthorized access and reducing the complexity of account management, allowing users to access scanner data without additional software installation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007857121000001
    Figure 0007857121000001
  • Figure 0007857121000002
    Figure 0007857121000002
  • Figure 0007857121000003
    Figure 0007857121000003
Patent Text Reader

Abstract

To provide a system for appropriately sharing a scanner in a simple procedure.SOLUTION: A file providing system includes a file generation apparatus, and a file providing apparatus which provides a data file generated by the file generation apparatus. The file generation apparatus includes: an authentication information generation unit which generates authentication information on condition that a request terminal which requests the data file has been connected to the same network as the file generation apparatus; and an authentication information transmission unit which transmits the authentication information generated by the authentication information generation unit to the request terminal and the file providing apparatus. The file providing apparatus includes: an authentication unit which performs authentication on the basis of the authentication information transmitted by the authentication information transmission unit and the authentication information received from the request terminal; and a file transmission unit which transmits, when the authentication of the authentication unit is successful, the data file generated by the file generation apparatus to the request terminal.SELECTED DRAWING: Figure 8
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a file providing system, a file providing method, and a program.

Background Art

[0002] For example, in Patent Document 1, scan data obtained by scanning is stored in the storage 104 of the digital multi-function device 1 in Patent Document 1, and the scan data processing module 502 transmits scan information regarding the digital multi-function device 10 which executed the scan and the user who executed the scan to the management server 101. The scan information management module 522 stores and manages the transmitted scan information, whereby the user can specify the storage location of his / her own scan data from the client terminal 102 to the management server 101 based on the scan information by the scan data acquisition module 541, and an image processing system for acquiring scan data from the multi-function device 103 which executed the scan at the client terminal 102 is disclosed.

[0003] Further, Patent Document 2 discloses an image input device control apparatus for controlling a control unit and an image input device associated with the control unit via a network, the apparatus including: authentication information acquisition means for acquiring authentication information; image data storage means for storing image data; storage area generation means for generating, within the image data storage means, a storage area in which an access right corresponding to the authentication information acquired by the authentication information acquisition means is set; and image acquisition means for acquiring the image data from the image input device and storing the image data in the storage area generated by the storage area generation means.

[0004] Furthermore, Patent Document 3 discloses a communication system in which a scanner 10 receives both account information AC1 for logging into an intermediary server 50 and account information AC2 for logging into a storage server 100 from a mobile terminal 150 using a single NFC communication, and after the scanner 10 logs into the intermediary server 50 using account information AC1, it sends scan data to the intermediary server 50 when it receives a scan instruction from the intermediary server 50, and the scanner 10 sends account information AC2 to the intermediary server 50 with account information AC1 and AC2 associated, and the intermediary server 50 logs into the storage server 100 using account information AC2 and sends scan data to the storage server 100.

[0005] Furthermore, Patent Document 4 discloses an image reading device comprising: a scan cloud ticket receiving unit that receives a scan cloud ticket, which is a data file that stores the contents of a job for storing scan data generated by an image reading device on a cloud server using login information to a cloud server; a startup operation input unit that inputs a startup operation to start a job in response to the reception of the scan cloud ticket; a scan data generation unit that performs image reading and generates scan data in response to the input of the startup operation; a login processing unit that obtains login information from the scan cloud ticket and logs in to the cloud server using the obtained login information; and an upload processing unit that uploads scan data from the image reading device to the cloud server. [Prior art documents] [Patent Documents]

[0006] [Patent Document 1] Japanese Patent Publication No. 2011-135522 [Patent Document 2] Japanese Patent Publication No. 2011-139341 [Patent Document 3] Japanese Patent Publication No. 2014-197820 [Patent Document 4] Japanese Patent Publication No. 2017-188880 [Overview of the project] [Problems that the invention aims to solve]

[0007] The objective is to provide a system that allows for the proper sharing of file generation devices through simple procedures. [Means for solving the problem]

[0008] The file provision system according to the present invention is a file provision system including a file generation device and a file provision device that provides data files generated by the file generation device, wherein the file generation device has an authentication information generation unit that generates authentication information on the condition that a requesting terminal requesting a data file is connected to the same network as the file generation device, and an authentication information transmission unit that transmits the authentication information generated by the authentication information generation unit to the requesting terminal and the file provision device, and the file provision device has an authentication unit that performs authentication based on the authentication information transmitted by the authentication information transmission unit and the authentication information received from the requesting terminal, and a file transmission unit that transmits the data file generated by the file generation device to the requesting terminal when authentication by the authentication unit is successful.

[0009] Preferably, the file providing device further includes an authorization registration unit that registers a requesting terminal that has successfully been authenticated by the authentication unit as a terminal that can grant other terminals permission to view data files, and the file transmission unit transmits the data file generated by the file generating device to other terminals that have been granted viewing permission by the requesting terminal registered by the authorization registration unit.

[0010] Preferably, the file generation device is a scanner with web server functionality, and the authentication information transmission unit returns the authentication information generated by the authentication information generation unit to the requesting terminal in response to a web access from the requesting terminal.

[0011] Preferably, the file generation device further includes an access information registration unit that registers Web access information for accessing the file generation device via the Web with the file provisioning device in association with device identification information that identifies the file generation device, and the file provisioning device further includes an access information notification unit that, when it receives device identification information from the requesting terminal, notifies the requesting terminal of the Web access information associated with the received device identification information.

[0012] Preferably, the file generation device further includes an initialization instruction unit that, when an initialization operation for initializing the file generation device is performed, transmits the device identification information of the file generation device to the file providing device and instructs the initialization of information related to the file generation device, and the file providing device further includes an initialization unit that, in response to an instruction from the initialization instruction unit, initializes the registration information associated with the received device identification information.

[0013] Furthermore, the file provision method according to the present invention is a file provision method including a file generation device and a file provision device that provides a data file generated by the file generation device, comprising: an authentication information generation step in which the file generation device generates authentication information on the condition that a requesting terminal requesting a data file is connected to the same network as the file generation device; an authentication information transmission step in which the file generation device transmits the authentication information generated in the authentication information generation step to the requesting terminal and the file provision device; an authentication step in which the file provision device performs authentication based on the authentication information transmitted in the authentication information transmission step and the authentication information received from the requesting terminal; and a file transmission step in which, if the authentication in the authentication step is successful, the file provision device transmits the data file generated by the file generation device to the requesting terminal.

[0014] Also, in a file providing system including a file generation device and a file providing device that provides a data file generated by the file generation device, when a request terminal that requests a data file is connected to the same network as the file generation device, an authentication information generation step of generating authentication information, and an authentication information transmission step of transmitting the authentication information generated in the authentication information generation step to the request terminal and the file providing device The aforementioned file generation device is executed by a computer.

Effect of the Invention

[0015] The file generation device can be appropriately shared with a simple procedure.

Brief Description of the Drawings

[0016] [Figure 1] It is a diagram illustrating the overall configuration of the file providing system 1. [Figure 2] It is a diagram explaining the outline of the processing in the file providing system 1. [Figure 3] It is a diagram illustrating the hardware configuration of the file providing server 2. [Figure 4] It is a diagram mainly illustrating the hardware configuration of the control part among the scanners 4. [Figure 5] It is a diagram illustrating the functional configuration of the file providing server 2. [Figure 6] It is a diagram illustrating the functional configuration of the scanner 4. [Figure 7] It is a diagram illustrating the information stored in the device information DB 370 of the file providing server 2. [Figure 8] It is a sequence diagram explaining the overall operation (S10) at the time of the first access in the file providing system 1. [Figure 9] It is a flowchart explaining the access processing (S20) after the second time in the file providing server 2. [Figure 10] It is a flowchart explaining the scanner initialization processing (S30) in the scanner 4. [Figure 11] It is a diagram illustrating a user addition screen 800, a login screen 802, a data display screen 804, and a scan screen 806. [Figure 12] It is a diagram illustrating an administrator screen and an initialization screen. [Figure 13] It is a diagram illustrating unauthorized access due to request forgery.

Embodiments for Carrying Out the Invention

[0017] Hereinafter, embodiments of the present invention will be described with reference to the drawings. FIG. 1 is a diagram illustrating the overall configuration of a file providing system 1. As illustrated in FIG. ********** 1, the file providing system 1 includes a file providing server 2, a scanner ********** 4, and a user terminal 6. The scanner 4 and the user terminal 6 are connected to the file providing server 2 via the Internet 7. In this example, the scanner 4 and the user terminal 6A are connected to the same local area network 70A (LAN 70A), and are connected to the file providing server 2 via this LAN 70A and the Internet 7. The LAN 70A is connected to the Internet 7 via a router 72A, and is a different network from the LAN 70B connected to the Internet 7 via a router 72B. That is, the user terminal 6A is a computer terminal belonging to a different network from the user terminal 6B. The file providing server 2 is a server device that temporarily stores the data file received from the scanner 4 in a temporary storage location, and returns the data file stored in the temporary storage location to the user terminal 6 in response to a request from the user terminal 6. It should be noted that there are some incomplete or unclear parts in the original text (such as , [Figure 11] , etc. in the first few lines and , , in the later part which seem to be incomplete tags), but I have translated it as accurately as possible based on the available content. If you can provide the complete and correct original text, the translation will be more accurate.Scanner 4 is an image reading device that optically reads an image from a document. Scanner 4 may connect directly to the network (LAN 70) via WiFi, or it may connect to the network (LAN 70) via a computer terminal. Scanner 4 may also send the image data itself read from the document to the file provision server 2, or it may perform data processing such as OCR on the image data read from the document and send the processing results to the file provision server 2. User terminal 6 is a computer terminal operated by the user, such as a tablet or smartphone.

[0018] In the above configuration, we want to be able to easily use scanner 4 from user terminal 6. Specifically, we want to be able to use scanner 4 without installing any driver software for scanner 4 on user terminal 6. Furthermore, users find managing account information (such as user IDs and passwords) cumbersome, so we want to make it possible to use Scanner 4 without account registration. One possible method for eliminating account registration is to use the Scanner 4's serial number as login information for the web application. However, since the serial number can be easily guessed, a third party who does not own Scanner 4 could potentially gain unauthorized access to the data. Furthermore, due to the limitations of web applications, unlike native applications, they cannot directly access scanner information. Therefore, the application cannot determine whether the device (scanner 4) corresponding to the serial number entered by the user is connected.

[0019] Therefore, in the file provision system 1 of this embodiment, as illustrated in Figure 2, unauthorized access by third parties is prevented, and access to the scanner 4 is made possible from the web application on the user terminal 6 by utilizing the following three points. (1) The user knows the serial number of scanner 4. (2) The scanner 4 and the user terminal 6 must be on the same network (to prevent external access). (3) Set up a web server inside scanner 4 (the URL will be generated based on the private IP address) (to provide a communication path between the web application and scanner 4). Furthermore, when the user terminal 6's web application communicates with the scanner 4, the scanner 4 generates a one-time password. This password is then shared among the three parties (scanner 4, file provision server 2, and the user terminal 6's web application). The file provision server 2 then determines whether the user owns the scanner 4, and only if the user does, grants access to the data files generated by the scanner 4.

[0020] Figure 3 illustrates the hardware configuration of the file provision server 2. Note that the file provision server 2 is an example of a file provision device according to the present invention. As illustrated in Figure 3, the file provision server 2 includes a CPU 200, memory 202, HDD 204, network interface 206 (network IF206), display device 208, and input device 210, and these components are connected to each other via a bus 212. CPU200 is, for example, the central processing unit. Memory 202 is, for example, volatile memory and functions as main memory. HDD204 is, for example, a hard disk drive, which stores computer programs (for example, server program 3 in Figure 5) and other data files as a non-volatile recording device. Network IF206 is an interface for wired or wireless communication, and for example, it enables connection to the Internet 7. The display device 208 is, for example, a liquid crystal display. The input device 210 is, for example, a keyboard and a mouse. In this example, the file provision server 2 is described as a physical server device, but it is not limited to this; for example, it could be a cloud server.

[0021] Figure 4 is a diagram illustrating the hardware configuration of the control unit portion of the scanner 4. As illustrated in Figure 4, the scanner 4 includes a CPU 400, volatile memory 402, non-volatile memory 404, a network interface 406 (network IF 406), and a touch panel 408, and these components are connected to each other via a bus 412. CPU400 is, for example, the central processing unit. Memory 402 is, for example, volatile memory and functions as main memory. The non-volatile memory 404 stores computer programs (e.g., the scanner program 5 in Figure 6) and other data files, for example, as a non-volatile recording device. The network interface IF406 is an interface for wired or wireless communication. The touch panel 408 is, for example, an LCD touch panel.

[0022] Figure 5 is a diagram illustrating the functional configuration of the file provision server 2. As illustrated in Figure 5, the file provision server 2 in this example has the server program 3 installed and running, and a device information database 370 (device information DB370) is configured. The server program 3 is stored on a recording medium such as a CD-ROM, and is installed on the file provision server 2 via this recording medium. The server program 3 includes a device information registration unit 300, an access information notification unit 310, an authentication unit 320, an authority registration unit 330, an initialization unit 340, and a file reply unit 350. Furthermore, some or all of the server program 3 may be implemented using hardware such as an ASIC, or it may be implemented by partially borrowing the functions of an OS (Operating System).

[0023] In server program 3, the device information registration unit 300 registers information about the file generation device in the device information DB 370, associating it with device identification information that identifies the file generation device. In this example, the device information registration unit 300 registers access information (URL) for accessing scanner 4 in the device information DB 370, associating it with the serial number of scanner 4.

[0024] When the access information notification unit 310 receives device identification information from the user terminal 6 (requesting terminal), it notifies the user terminal 6 of the web access information associated with the received device identification information. The web access information is, for example, a URL. In this example, when the access information notification unit 310 receives the serial number of the scanner 4 via the web application of the user terminal 6, it reads the URL associated with the received serial number from the device information DB 370, sends the read URL back to the user terminal 6, and redirects it to the scanner 4 corresponding to this URL.

[0025] The authentication unit 320 performs authentication based on the authentication information received from the scanner 4 (authentication information transmission unit 520 in Figure 6) and the authentication information received from the user terminal 6. In this example, the authentication unit 320 compares the one-time password received from the scanner 4 with the one-time password received from the user terminal 6 within a predetermined period, and determines that authentication is successful if these one-time passwords match.

[0026] The authorization registration unit 330 registers the user terminal 6, which has been successfully authenticated by the authentication unit 320, in the device information DB 370 as an administrator terminal that can grant other terminals permission to view data files. Administrator privileges include the permission to grant other terminals permission to view data files and the permission to view and retrieve data files generated by the scanner 4. In this example, the authorization registration unit 330 registers the cookie of the user terminal 6, which has been successfully authenticated by the authentication unit 320, in the device information DB 370 as the cookie of the administrator terminal.

[0027] The initialization unit 340 initializes the registration information associated with the received device identification information in response to instructions from the scanner 4 (initialization instruction unit 540 in Figure 6). In this example, the initialization unit 340 deletes the information associated with the serial number received from the scanner 4 (initialization instruction unit 540 in Figure 6) from the device information DB 370.

[0028] The file reply unit 350 sends the data file generated by the scanner 4 to the user terminal 6 to which administrator privileges have been granted by the authority registration unit 330 (i.e., the user terminal 6 that has successfully been authenticated by the authentication unit 320). In this example, the file reply unit 350 sends back a list of scan data scanned by the scanner 4, specifying the user terminal 6, to the user terminal 6 to which administrator privileges have been granted by the authority registration unit 330, and sends the selected scan data from the list to the user terminal 6. Furthermore, the file reply unit 350 sends the data files generated by the scanner 4 from the user terminal 6, which has been granted administrator privileges by the privilege registration unit 330, to other terminals that have been granted viewing privileges. In this example, the file reply unit 350 specifies the user terminal 6, which has been granted administrator privileges, and sends a list of scan data scanned by the scanner 4 back to the other terminals that have been granted viewing privileges, and sends the selected scan data from the list to the terminal.

[0029] Figure 6 is a diagram illustrating the functional configuration of scanner 4. As illustrated in Figure 6, scanner program 5 is installed and operates on scanner 4 in this example. Although scanner program 5 is pre-installed on scanner 4 in this example, it is not limited to this; for example, it may be stored on a recording medium such as a CD-ROM and installed on scanner 4 via this recording medium. The scanner program 5 includes an access information registration unit 500, an authentication information generation unit 510, an authentication information transmission unit 520, a web server generation unit 530, an initialization instruction unit 540, a data file generation unit 550, and a data file transfer unit 560. Furthermore, part or all of the scanner program 5 may be implemented using hardware such as an ASIC, or it may be implemented by partially utilizing the functions of the OS (Operating System).

[0030] In scanner program 5, the access information registration unit 500 registers Web access information for accessing the scanner 4 via the Web with the file provision server 2, associating it with device identification information that identifies the scanner 4. In this example, the access information registration unit 500 registers a URL generated based on the scanner 4's private IP address with the file provision server 2, associating it with the scanner 4's serial number.

[0031] The authentication information generation unit 510 generates authentication information on the condition that the user terminal 6 requesting the data file is connected to the same network (LAN 70) as the scanner 4. In this example, the authentication information generation unit 510 generates a one-time password that is valid for a predetermined period of time, on the condition that the user terminal 6 requesting the data file is connected to the same LAN 70 as the scanner 4.

[0032] The authentication information transmission unit 520 transmits the authentication information generated by the authentication information generation unit 510 to the user terminal 6 and the file provision server 2. In this example, the authentication information transmission unit 520 transmits the one-time password generated by the authentication information generation unit 510 to the user terminal 6 requesting the data file and to the file provision server 2.

[0033] The web server generation unit 530 activates the web server function within the scanner 4. In this example, the web server generation unit 530 generates a web server using the scanner 4's private ID address and implements the function of responding to web requests from user terminals 6 within the same LAN.

[0034] When an initialization operation is performed to initialize the scanner 4, the initialization instruction unit 540 sends the device identification information of the scanner 4 to the file provision server 2 and instructs the initialization of information related to the scanner 4. In this example, when an initialization operation is performed by the user, the initialization instruction unit 540 sends the serial number and username of the scanner 4 to the file provision server 2 and causes the information associated with this serial number and username to be deleted from the device information DB 370.

[0035] The data file generation unit 550 controls the scanner 4 to generate a data file. In this example, the data file generation unit 550 controls the scanner 4 in response to a scan operation by the user to read image data from the original document and generates scan data based on the read image data. The scan data may be image data that has undergone predetermined image processing, or it may be string information extracted from the image data by OCR processing.

[0036] The data file transfer unit 560 transfers the data file generated by the data file generation unit 550 to the file provision server 2, associating it with the device identification information of the scanner 4. In this example, the data file transfer unit 560 transfers the scan data generated by the data file generation unit 550 to the file provision server 2, associating it with the serial number and user name of the scanner 4. The transferred scan data is temporarily stored in the device information DB 370, associating it with the serial number and user name.

[0037] Figure 7 is an example of the information stored in the device information DB370 of the file provision server 2. As illustrated in Figure 7, the file provision server 2 stores device management information and file management information. The device management information registers the serial number that identifies scanner 4, the URL for accessing scanner 4, the one-time password received from scanner 4, and the cookie of the user terminal 6 that successfully authenticated with this one-time password, all of which are associated with each other. The file management information registers the identification information of the file transferred from scanner 4, the cookie of the user terminal that has administrator privileges for this file, and the cookie of the user terminal that has viewing privileges for this file, all of which are associated with each other.

[0038] Figure 8 is a sequence diagram illustrating the overall operation (S10) during the first access in the file provisioning system 1. As illustrated in Figure 8, in step 100 (S100), the user adds a user to the scanner 4 by operating the touch panel 408 of the scanner 4. Specifically, the scanner 4 displays the user addition screen 800, illustrated in Figure 11(A), on the touch panel 408 and accepts the user name input operation. In step 102 (S102), the scanner 4 (Web server generation unit 530) starts a Web server within itself (scanner 4). The IP address of the Web server is a private IP address. In step 104 (S104), the scanner 4 (access information registration unit 500) notifies the file provision server 2 of the URL for accessing the started web server and the serial number of its own device (scanner 4).

[0039] In step 106 (S106), the file provision server 2 (device information registration unit 300) associates the URL and serial number notified from the scanner 4 with each other and registers them in the device information DB 370. In step 108 (S108), the file provision server 2 notifies the scanner 4 that the registration of the URL and serial number has been completed. In step 110 (S110), the scanner 4 displays a message indicating that the file provision server 2 is ready and prompts the user to log in using the web application on the user terminal 6.

[0040] In step 112 (S112), the user terminal 6 launches the web application and enters the serial number of the scanner 4. Specifically, the user terminal 6 displays the login screen 802 illustrated in Figure 11(B) and accepts the input of the serial number of the scanner 4. In step 114 (S114), the user terminal 6 sends the entered serial number to the file provision server 2. In step 116 (S116), the file provision server 2 (access information notification unit 310) reads the URL associated with the serial number received from the user terminal 6 from the device information DB 370 and sends the read URL back to the user terminal 6.

[0041] In step 118 (S118), the user terminal 6 automatically accesses the scanner 4 based on the URL received from the file provision server 2. In step 120 (S120), the scanner 4 (authentication information generation unit 510) generates a one-time password, provided that the user terminal 6 that accessed the Web is connected to the same network (LAN 70A). In step 122 (S122), the scanner 4 (authentication information transmission unit 520) notifies the file provision server 2 of the generated one-time password. In step 124 (S124), the scanner 4 (authentication information transmission unit 520) further notifies the user terminal 6 of the same one-time password.

[0042] In step 126 (S126), the user terminal 6 uses the one-time password notified by the scanner 4 to send an authentication request to the file provision server 2. In step 128 (S128), the file provision server 2 (authentication unit 320) compares the one-time password notified from the scanner 4 with the one-time password received from the user terminal 6 and performs authentication. In step 130 (S130), the file provision server 2 (authority registration unit 330) registers the cookie of the user terminal 6 that successfully authenticated in the device information DB 370 as belonging to a terminal with administrator privileges.

[0043] In step 132 (S132), the file provision server 2 notifies the user terminal 6 that the user addition has been successfully completed. Once the user addition is complete, as illustrated in Figure 11 (D), the scanner 4's touch panel 408 displays a scan screen 806 with the added user name. In step 134 (S134), the user terminal 6 requests scan data. In step 136 (S136), the file provision server 2 (file transmission unit 350) identifies the user terminal 6 that requested the scan data as having administrator privileges based on the user terminal 6's cookie, and then returns a list of scan data scanned by the scanner 4 under this username to the user terminal 6. As a result, the data display screen 804, as illustrated in Figure 11(C), is displayed on the user terminal 6, and the desired scan data can be obtained from the data list.

[0044] Figure 9 is a flowchart illustrating the second and subsequent access processing (S20) on the file provision server 2. As shown in Figure 9, in step 200 (S200), when the authorization registration unit 330 of the file provision server 2 detects a Web access from the user terminal 6, it identifies the authorization of the user terminal 6 based on the cookie. In step 205 (S205), the authorization registration unit 330 instructs the file transmission unit 350 to return the list if the user terminal 6 that accessed the Web has administrator privileges, and proceeds to the process in S225. If the user terminal 6 that accessed the Web does not have administrator privileges, it proceeds to the process in S210.

[0045] In step 210 (S210), the authorization registration unit 330 instructs the file transmission unit 350 to return the list if the user terminal 6 that accessed the Web has viewing privileges, and proceeds to the process in S225. If the user terminal 6 that accessed the Web does not have viewing privileges, it proceeds to the process in S215. In step 215 (S215), the authorization registration unit 330 displays a message to the user terminal 6 indicating that permission from the user terminal 6, which has administrator privileges, is required.

[0046] In step 220 (S220), the authorization registration unit 330 displays the administrator screen illustrated in Figure 12(A) to a user terminal 6 with administrator privileges and accepts an operation to grant viewing privileges. When the authorization registration unit 330 accepts an operation to grant viewing privileges, it registers the cookie of the terminal to which viewing privileges have been granted in association with the viewing privileges and proceeds to the process in S225. If the operation to grant viewing privileges is not accepted within a predetermined period, it proceeds to the process in S230. In step 225 (S225), the file transmission unit 540 sends a list of scan data back to the user terminal 6 and transmits the selected scan data from the list to the user terminal 6. In step 230 (S230), the authorization registration unit 330 displays a message to the user terminal 6 indicating that access to the scanned data is unavailable.

[0047] Figure 10 is a flowchart illustrating the scanner initialization process (S30) in scanner 4. As shown in Figure 10, in step 300 (S300), the initialization instruction unit 540 of the scanner 4 displays the initialization screen illustrated in Figure 12(B) on the touch panel 408 to accept an initialization operation from the user. The initialization instruction unit 540 waits until it accepts an initialization operation (S300: No), and if it accepts an initialization operation (S300: Yes), it proceeds to the process in S305. In step 305 (S305), the initialization instruction unit 540 specifies the serial number and user name of the scanner 4 and instructs the file provision server 2 to initialize it. The file provision server 2 then uses the initialization unit 340 to delete the information associated with the serial number and user name specified by the initialization instruction unit 540 from the device information DB 370.

[0048] In step 310 (S310), the initialization instruction unit 540 waits until it receives an initialization completion notification from the file provision server 2 (S310: No), and when it receives the initialization completion notification from the file provision server 2, it proceeds to the process in S315. In step 315 (S315), the initialization instruction unit 540 displays on the touch panel 408 that the initialization process specified by the user has been completed. This prevents information about the previous owner from remaining on the file provision server 2 when the ownership of scanner 4 changes, and also prevents unnecessary inquiries from being sent to user terminals 6 that have administrator privileges.

[0049] As explained above, according to the file provision system 1 of this embodiment, the serial number of the scanner 4 is used as a key to notify the scanner 4 of a URL for web access. When a web access is made based on this URL, the scanner 4 generates a one-time password, provided that the user terminal 6 is on the same network, and notifies the file provision server 2 and the user terminal 6 of the generated one-time password. This prevents unauthorized access by third parties, even though account registration is not required. Specifically, as illustrated in Figure 13, suppose a request for password transmission is made to the file provision server 2 from a terminal on a different network from the scanner 4. At this time, there is no way for the terminal that has accessed the system without authorization to obtain the one-time password issued by the scanner 4 in step 7. As a result, a mismatch occurs in the verification of the one-time password in step 10, and access to the scanned data fails.

[0050] Although embodiments of the present invention have been described, these embodiments are presented as examples only and are not intended to limit the scope of the invention. The above embodiments can be implemented in various other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. The above embodiments and their variations are included in the scope and spirit of the invention, as well as in the claims and their equivalents. [Explanation of Symbols]

[0051] 1. File provision system 2 File provision server 3 Server Program 4 Scanners 5 Scanner Programs 6. User terminals

Claims

1. A file provision system including a file generation device and a file provision device that provides data files generated by the file generation device, The aforementioned file generation device, A certification information generation unit generates certification information on the condition that the requesting terminal requesting the data file is connected to the same network as the file generation device, A transmission unit transmits the authentication information generated by the authentication information generation unit to the requesting terminal and the file provisioning device. It has, The aforementioned file provisioning device, An authentication unit that performs authentication based on the authentication information transmitted by the authentication information transmission unit and the authentication information received from the requesting terminal, If authentication by the authentication unit is successful, the file transmission unit transmits the data file generated by the file generation device to the requesting terminal. has File sharing system.

2. The aforementioned file provisioning device, The authorization registration unit registers the requesting terminal that has successfully been authenticated by the aforementioned authentication unit as a terminal that can be granted data file viewing privileges to other terminals. It further possesses, The file transmission unit transmits the data file generated by the file generation device to other terminals that have been granted viewing privileges by the requesting terminal registered by the authorization registration unit. The file provision system according to claim 1.

3. The aforementioned file generation device is a scanner with web server functionality. The authentication information transmission unit sends back the authentication information generated by the authentication information generation unit to the requesting terminal in response to the requesting terminal's Web access. The file provision system according to claim 2.

4. The aforementioned file generation device, Access information registration unit registers web access information for web access to this file generation device in the file provisioning device, associating it with device identification information that identifies this file generation device. It further possesses, The aforementioned file provisioning device, When the access information notification unit receives device identification information from the requesting terminal, it notifies the requesting terminal of the Web access information associated with the received device identification information. It further possesses The file provision system according to claim 3.

5. The aforementioned file generation device, When an initialization operation is performed to initialize the file generation device, the initialization instruction unit transmits the device identification information of the file generation device to the file provisioning device and instructs the initialization of information related to the file generation device. It further possesses, The aforementioned file provisioning device, Initialization unit initializes the registration information associated with the received device identification information in response to instructions from the initialization instruction unit. It further possesses The file provision system according to claim 4.

6. A file provision method comprising a file generation device and a file provision device that provides data files generated by the file generation device, The file generation device generates authentication information on the condition that the requesting terminal requesting the data file is connected to the same network as the file generation device; The file generation device includes an authentication information transmission step in which it transmits the authentication information generated in the authentication information generation step to the requesting terminal and the file providing device, The file provisioning device performs an authentication step based on the authentication information transmitted in the authentication information transmission step and the authentication information received from the requesting terminal. If the file providing device successfully authenticates in the authentication step, it performs a file transmission step in which it transmits the data file generated by the file generating device to the requesting terminal. A method for providing files that have the following characteristics.

7. In a file provision system including a file generation device and a file provision device that provides data files generated by the file generation device, A signature information generation step that generates signature information, provided that the requesting terminal requesting the data file is connected to the same network as the file generation device, A transmission step of authentication information that transmits the authentication information generated in the authentication information generation step to the requesting terminal and the file providing device. A program that causes the computer of the file generation device to execute the following.