Printing system and printing control method
The printing system addresses security issues in cloud printing by associating guest users with their print jobs and canceling jobs without passwords, ensuring secure execution of authorized print tasks.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- CANON KK
- Filing Date
- 2022-06-09
- Publication Date
- 2026-06-03
AI Technical Summary
In cloud printing systems, guest users can access and execute print jobs without proper user association, leading to security issues as multiple guest users can access and execute each other's print jobs.
A printing system that associates guest users with their print jobs through a printing service system, ensuring that print jobs without a set password are canceled, and only print jobs with a password are executed.
Ensures security for guest users' print jobs by preventing unauthorized access and execution of print jobs without a password, thereby maintaining user-specific job integrity.
Smart Images

Figure 0007869689000001 
Figure 0007869689000002 
Figure 0007869689000003
Abstract
Description
Technical Field
[0001] The present invention relates to a printing system and a printing control method.
Background Art
[0002] In a printing apparatus installed in an organization or company and assumed to be used by a plurality of users, a user management function may be enabled. In this case, users belonging to an organization or company have a mechanism to log in to the printing apparatus and use each function of the printing apparatus. In addition, users not belonging to an organization or company can log in as guest accounts, and there is a mechanism to permit the submission of jobs to the printing apparatus within the range that satisfies the set restrictions (Patent Document 2).
[0003] In recent years, a cloud printing mechanism for submitting a printing job via the cloud and transmitting the printing job to a printing apparatus has begun to spread (Patent Document 1). In such a printing system, first, an administrator registers the printing apparatus with a cloud printing service (hereinafter also referred to as CPS) to which the administrator belongs. Thereafter, users permitted to use CPS select a printer registered with CPS as an output printer using their respective client terminals, perform desired printing settings, and submit a printing job to CPS. CPS that has received the printing job transfers the printing job to the selected printing apparatus. The printing apparatus executes printing based on the transferred printing job. In particular, the mechanism of cloud printing using IPP (Internet Printer Procotol) is defined in PWG5100.18, RFC3995, RFC3996, and the like.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Patent Document 2
[0005] Incidentally, some cloud services offer mechanisms to temporarily allow users who are not registered with the cloud service to use it. For example, a CPS administrator can grant a specific guest user who is not registered to use the CPS. The guest user may then be granted permission to use, for example, cloud printing through the CPS. On the other hand, some printing devices can also be used by logging in as a guest user.
[0006] When a guest user of a CPS selects a printer and executes a print job to the CPS, and the printer retrieves and saves that print job from the CPS, it is not possible to associate the user who submitted the print job (i.e., the owner) with a registered user of the printer. In this case, the printer treats the retrieved print job as a print job belonging to the guest user. If multiple guest users of the CPS execute print jobs to the CPS, a problem arises where all of those print jobs can be accessed and executed by the guest users of the printer as their own print jobs.
[0007] This invention has been made in view of at least one of the above-mentioned problems. One aspect of this invention is to provide a mechanism that ensures security even for guest users' print jobs. [Means for solving the problem]
[0008] To achieve at least one of the above objectives, the present invention has the following configuration. According to one aspect of the present invention, a printing system comprising a printing apparatus, a printing service system connected to the printing apparatus, and an information processing device connected to the printing service system, The printing service system includes registration means for registering the printing device and storage means for storing print jobs received from the information processing device. The information processing device has a transmission means for transmitting a print job from a logged-in user to the print service system, specifying a print device selected from among the print devices registered in the print service system. The printing device includes storage means for storing users of the printing service system in association with users of the printing device, and printing means for retrieving print jobs of users associated with the logged-in user of the printing device from among the print jobs stored in the printing service system and executing printing. The guest users of the printing service system are linked to the guest users of the printing device. Regarding the print job of the aforementioned guest user for whom no password has been set: hand, The printing apparatus This cancels the print job of the guest user for whom the password is not set and does not execute the print job. A printing system characterized by the above is provided. [Effects of the Invention]
[0009] According to the present invention, security can also be ensured for guest users' print jobs. [Brief explanation of the drawing]
[0010] [Figure 1] This is a diagram showing an example of a printing system. [Figure 2] This is a diagram illustrating the list of user accounts. [Figure 3] This figure shows an example of the operation screen of a printing device. [Figure 4] This figure shows an example of the hardware configuration of a printing device. [Figure 5] This is an example of a flowchart for acquiring a print job in the first embodiment. [Figure 6] This is an example of a packet received when a print job is received in the first embodiment. [Figure 7]An example of a flowchart at the time of obtaining a print job in the second embodiment. [Figure 8] An example of a flowchart for registering printer capability information in the third embodiment. [Figure 9] An example of a packet for registering printer capability information in the third embodiment. [Figure 10] A diagram showing an example of the hardware configuration of a client terminal. [Figure 11] An example of a flowchart for discriminating a user in the fourth embodiment. [Figure 12] An example of a print setting screen in the fourth embodiment. [Figure 13A] An example of a sequence (registration of a printing device) of cloud printing using IPP. [Figure 13B] An example of a sequence (printing) of cloud printing using IPP. [Figure 14] An example of a flowchart for discriminating a user in the fifth embodiment. [Figure 15A] An example of a sequence of obtaining a print job in the first embodiment. [Figure 15B] An example of a sequence of obtaining a print job in the second embodiment.
MODE FOR CARRYING OUT THE INVENTION
[0011] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the invention according to the claims. Although a plurality of features are described in the embodiments, not all of these plurality of features are essential for the invention, and the plurality of features may be arbitrarily combined. Further, in the accompanying drawings, the same or similar configurations are denoted by the same reference numerals, and redundant descriptions are omitted.
[0012] <The First Embodiment> First, the configuration of the printing system according to the present invention will be explained using Figure 1. The printing system according to this embodiment includes a printing device 101, client terminals 103 to 104, a cloud print service (hereinafter also referred to as CPS) 102, a cloud ID service provider 105, and a cloud ID service provider 107. Here, CPS 102 and cloud ID service 105 are cloud services 106 provided by the same company, and CPS 102 can be used with an account managed by the cloud ID service provider 105. CPS 102 is also referred to as the printing service system.
[0013] On the other hand, the cloud ID service provider 107 is a service provided by a different company than the cloud service 106. Users who have an account with the cloud ID service provider 107 can use the CPS 102 as guest users by using an account linking service such as OAuth with that account. The printing device 101 communicates with the CPS 102 on the internet via the network 100. The network 100 may be configured by combining, for example, a communication network such as a LAN or WAN, a cellular network (for example, LTE or 5G), or a wireless network compliant with IEEE 802.11. In other words, the network 100 only needs to be capable of sending and receiving data, and any communication method can be adopted for the physical layer.
[0014] The printing device 101 has a scanning function that transmits data based on an image obtained using a scanner to an external device, a printing function that prints an image onto a sheet such as paper based on a print job received from an external device, and a copying function. The printing device 101 can also receive print jobs via the CPS 102 and perform printing. In this embodiment, a Multi-Function Peripheral (MFP) with multiple functions is given as an example of a printing device, but it is not limited to this. For example, a Single-Function Peripheral (SFP) with only a printing function may also be used. In addition, in this embodiment, printing onto a sheet such as paper is given as an example, but it is not limited to this, and it can also be applied to print control in 3D printing, which forms three-dimensional objects based on three-dimensional shape data. Note that the printing device is sometimes called an image forming apparatus.
[0015] Furthermore, the printing device 101 of this embodiment has a user management function. User information is registered in advance in the printing device 101, and the device provides function restrictions that limit the functions that can be used by the user, as well as a login function that allows users to log in to the printing device to use it.
[0016] CPS102 receives print jobs from client terminals such as client terminals 103-104 and saves the print jobs. Subsequently, it notifies the printing device 101 registered with CPS102 that a print job has been submitted. Upon receiving this notification, the printing device 101 acquires the print job and executes the printing process. CPS102 may consist of one or more information processing devices. If it consists of multiple information processing devices, functions such as user authentication and print data provision may be distributed, the load of a single function may be distributed, or a combination of these may be used.
[0017] <Hardware configuration of the printing device 101> The hardware configuration of the printing device 101 in this embodiment will be explained with reference to Figure 4. Figure 4 is a block diagram showing the hardware configuration of the printing device 101. The printing device 101 has a reading function for reading images on a sheet, a file transmission function for transmitting the read images to an external communication device, and so on. It also has a printing function for printing images onto a sheet. Furthermore, it is assumed that it has a function for receiving and printing print jobs from the CPS 102, as well as the user management function and hold-print function mentioned above.
[0018] The CPU (Central Processing Unit) 401 controls the operation of the entire printing device 101. The CPU 401 reads and executes control programs stored in the ROM (Read Only Memory) 402 or storage 404 to perform various controls such as print control and read control. The ROM 402 stores control programs that can be executed by the CPU 401. The RAM (Random Access Memory) 403 is the main memory accessed by the CPU 401 and is used as a work area or temporary storage area for deploying various control programs. The storage 404 stores print jobs, image data, various programs, and various setting information. Print jobs and other information downloaded from the CPS 102 are also stored in the storage 404. In this way, the hardware such as the CPU 401, ROM 402, RAM 403, and storage 404 constitute a so-called computer.
[0019] In this embodiment, the printing apparatus 101 uses one CPU 401 and one memory (RAM 403) to execute each process shown in the flowchart described later, but other configurations are also possible. For example, multiple processors, memories, and storage can work together to execute each process shown in the flowchart described later. Alternatively, some processes may be executed using hardware circuits.
[0020] The printer 410 prints an image on a sheet fed from a paper cassette (not shown) based on the input print image and print control commands. The printing method may be an electrophotographic method that transfers and fixes toner onto paper, or an inkjet method that prints by ejecting ink onto paper.
[0021] The scanner 408 reads a document placed on a document glass (not shown) and generates image data. The image data generated by the scanner 408 can be printed by the printer 410, stored in the storage 404, or transmitted to an external device via the network interface (I / F) 411.
[0022] The control unit 406 is equipped with a liquid crystal display with touch panel functionality and various hard keys. The control unit 406 functions as a display unit that shows information to the user and a reception unit that receives user instructions. In other words, the control unit 406 provides a user interface. The CPU 401 works in cooperation with the control unit 406 to control the display of information and the reception of user operations.
[0023] The network interface 411 is connected to a network cable and can communicate with external devices on network 100 or the internet. In this embodiment, it is assumed that the communication interface is a wired communication interface compliant with Ethernet®, but it is not limited to this. For example, it may be a wireless communication interface compliant with the IEEE 802.11 series. Also, both may be wireless communication interfaces. Furthermore, it may be a communication interface for mobile communication such as 3G lines such as CDMA, 4G lines such as LTE, or 5G NR.
[0024] This embodiment illustrates a case where the printer 101 manages a database for managing user accounts, but it is not limited to this. User account management for users of the printer 101 can also be achieved in cooperation with an external authentication server. For example, user accounts may be managed in cooperation with the Active Directory service provided by Microsoft® or the Azure® Active Directory service.
[0025] <Hardware configuration of Cloud Print Service 102> The hardware configuration of the cloud print service 102 in this embodiment will be explained using Figure 10. The CPUs 1001 to 1006 in Figure 10 correspond to the CPUs 201 to 206 in Figure 2, and the network interface 1007 corresponds to the network interface 411. Since each component in Figure 10 is almost identical to the components of the printing device in the corresponding Figure 4, a detailed explanation will be omitted. The client terminal also has a similar configuration to that in Figure 10. Furthermore, the CPS 102 may have multiple CPUs and memories. In that case, at least one program may be stored in each of the multiple memories.
[0026] <Register a print job> The procedure for enabling printing using the printing system configured as described above in this embodiment will be explained. Figure 13A is an example of a sequence diagram showing the mechanism of cloud printing using IPP, in particular the procedure for registering a printing device and making the registered printing device available from a client terminal.
[0027] First, the printer 101 sends a printer registration request to the CPS 102 through operation (S1601). This operation can be performed using the control panel 206 of the printer 101, or it can be performed using the remote UI provided by the printer 101 to a computer or the like. Subsequently, the printer 101 notifies the CPS 102 of the supported attribute information and attribute values using the Update-Output-Device-Attributes operation (S1602). This registers the attribute values of the printer 101 in the CPS 102. The attribute values of the printer 101 include, for example, whether or not it supports PIN printing, which is a print job with a password.
[0028] Subsequently, the printing device registers the event notification to CPS102 using the Create-Printer-Subscription operation (S1603). After registering the notification, the printing device 101 checks whether an event has occurred using the Get-Notification operation (S1604). As a result, when a new event occurs, such as the registration of a print job to be executed by the printing device 101, CPS102 notifies the printing device 101 of the event. Adding the printing device to CPS102 using the above procedure only needs to be done prior to cloud printing using the printing device 101.
[0029] Furthermore, when registering the printer, the user of CPS102 is linked to the user of printer 101, and the user information of that user is saved. For example, the user information of CPS102 may be linked to the user information of printer 101 and saved in printer 101. In addition to the user ID, the user information may also include authentication information such as a password if necessary. This user linking may be performed from the control panel of printer 101, or it may be performed from a client terminal using its remote UI, etc. Regardless of how it is done, it is desirable to allow only administrator users with administrator privileges to perform this linking operation. Also, this user linking may be performed after the registration of printer 101.
[0030] Meanwhile, the client terminal 103 searches for the printers registered in the CPS 102 and adds a selected printer to the client terminal 103 as the printer to be used (S1605). Then, it retrieves the attribute information and attribute values of the added printer from the CPS 102 using the Get-Printer-Attributes operation (S1606). The retrieved attribute information and attribute values of the printer may be saved in association with the registered printer. Note that the password attribute (PIN attribute), which indicates that the printer supports password-protected print jobs, i.e., PIN printing, is also included in the attribute information of the printer.
[0031] After this, when the client terminal 103 executes a print job, it can select the print device added in S1605 and S1606, and then print using the selected print device. When printing, if the print device selected by the client terminal 103 is the print device 101 registered in CPS102, the print settings screen is displayed according to the acquired attribute information, and the print job is sent to CPS102 along with the configured print attributes. Note that the attribute information of the print device is sometimes referred to as the print settings.
[0032] <Guest job on cloud printing service> Next, we will explain the conventional guest jobs in the cloud print service. Figure 2(A) is an example of a list of user accounts registered in cloud service 106. User A and User B are legitimate users registered with the cloud ID service provider. The cloud service administrator can set each user to be allowed or denied to use CPS102. Guest users A and B are users not registered with cloud service 106, and are users of another cloud ID service provider 107. Normally, guest users A and B do not have the right to use CPS102, but let's assume that the administrator of cloud service 106 has set them to allow the use of CPS102. In this case, guest users A and B can use CPS102 using their accounts with cloud ID service provider 107. Such integration is achieved using service integration technologies such as OAuth.
[0033] On the other hand, as shown in Figure 2(B), the printer 101 has information on users A and B registered, and users who are not registered are treated as guest users. Registered users of the printer 101 are linked to registered users of CPS102 when the printer 101 is registered with CPS102, for example. For example, the user information of a registered user of CPS102 linked to a registered user of the printer 101 is stored in the printer 101. As a result, if a user of the printer 101 is logged into the printer 101, the printer can access CPS102 using the user information of CPS102 linked to that user. Users not registered in CPS102 cannot be linked to users of the printer. Therefore, if guest user A or guest user B sends a print job using CPS102, the printer 101 will treat these guest user print jobs as guest user print jobs. To explain the challenges of guest jobs in the cloud print service, we will explain printing from regular users and printing from guest users separately. First, we will explain the procedure for the cloud printer.
[0034] ●Example of Cloud Print Procedure Figure 13B shows an example of the procedure for performing cloud printing after registering the printing device as shown in Figure 13A. This procedure is also performed in accordance with IPP. The client terminal 103 displays the print settings screen according to the acquired attribute information and attribute values, and sends the print job to the CPS 102 according to the print attributes specified by the user (S1607). The print job shall be sent using one of the operations that send print jobs, such as the Send-Document operation, Print-Job operation, or Create-Job operation.
[0035] The CPS sends an event notification to the printer 101 indicating that a job has been submitted (S1608). Upon receiving it, the printer 101 requests job list information from the CPS 102 using the Get-Jobs operation (S1609) and obtains the job list information from the CPS 102 (S1609-2). Furthermore, it requests the CPS 102 to provide selected job data and attribute values from the obtained job list using the Fetch-Job operation (S1610) and obtains the job based on the response (S1610-2).
[0036] The printer 101 executes the printing process according to the acquired job data and attribute values (S1611). Then, depending on the job processing status, it sends a printer information notification from the printer 101 to the CPS 102 using the Update-Output-Device-Attributes operation (S1612, S1614). It also sends a job information notification from the printer 101 to the CPS 102 using the Update-Job-Status operation (S1613). Once the printing process is complete, the client terminal is also notified of the completion of printing from the CPS 102 (S1615).
[0037] In this specification, CPS (Cloud Print Service) refers to a service that can communicate with client terminals and printers via the internet, receives print requests using IPP, and provides print jobs. This procedure describes the case where a legitimate user prints without using the PIN printing function. With PIN printing, a PIN (Personal ID Number, i.e., a password) is set for the print job sent to CPS 102. When the printing device 101 executes the print job, the user is prompted to enter a password, and if the entered password matches the set password, printing is executed.
[0038] The job information acquisition request packet shown in Figure 6(A) requests a print job with job ID=1. If this print job is from a legitimate user, the packet example will be as shown in Figure 6(B). Figure 6(B) is an example of a job acquisition response packet received by the printer 101 in step S1610-2 of Figure 13B. This is an example where UserA submitted a print job, and the "Job-originating-user-uri" contains tenant information that indicates it is an account from the cloud ID service provider 105. From this, the printer 101 can determine that this print job is from a legitimate user. Therefore, when UserA logs into the printer 101, it is possible to control the display so that only jobs submitted by UserA are shown, as shown in Figure 3(B). For the sake of explanation, the CPS user and the printer user linked to each other will be described as the same user. However, the user IDs of these users may be different as long as they are linked.
[0039] Next, we will explain the case where a guest user prints. A guest user's print job will take the form of an example packet as shown in Figure 6(C). In this example, we will explain using a user named guestA and an account with the cloud ID service provider 107, guestA@google.com. The printer 101 determines that the print is from an account not registered with the printer 101 and saves the acquired print job as a guest user job on the printer 101.
[0040] On the other hand, in order to log in to the printer 101 as a guest user, for example, a button for logging in as a guest user is placed on the login screen displayed on the operation unit 406. Users who wish to log in as a guest user can do so by touching that button. Therefore, when a user with the username guestA logs in to the printer 101 as a guest user, not only guestA's print jobs but also those of all other guest users, such as guestB, are displayed, as shown in Figure 3(C). A guest user can then select guestB's print job, which is not their own, and execute the print job.
[0041] Thus, if multiple guest users attempt to print to the CPS, when a guest user logs into the printer 101, they can access and execute print jobs for all guest users.
[0042] <Sequence of sending and receiving print jobs in the first embodiment> Next, the print job acquisition sequence in this embodiment will be explained using Figures 5 and 15A. In this embodiment, the printer 101 acquires and executes only print jobs of guest users for whom a PIN has been set, thereby restricting the execution of prints by guest users. Figure 15A starts with the printer 101 registered with the CPS 102 in the sequence of Figure 13A. This procedure is also performed in accordance with IPP. In this embodiment, the case of "immediate job acquisition" after the client terminal sends a print job to the CPS 102 and the CPS 102 sends a job event notification to the printer 101 will be explained in S1501 to S1503 of Figure 15A.
[0043] First, on the client terminal 103, the guest user selects the printer 101 and sends the print job to the CPS 102 (S1501). At this time, a PIN may or may not be set for the print job. However, as described later, the printer 101 cannot execute a print job for which a PIN is not set. The CPS 102 saves the received print job (S1502) and sends an event notification to the printer 101 (S1503).
[0044] The CPU of the printing device 101 receives an event notification from CPS102 that a print job has been submitted to CPS102 (S1503, S501). Next, as shown in Figure 6(A), it sends a "Fetch-job" request operation to CPS012, which is a job acquisition request specifying the job ID to be acquired (S1504, S502). Then, the CPU of the printing device 101 receives a job acquisition response containing job data from CPS102 as shown in Figures 6(B) to (D) (S1505, S503). In S503, it checks the job owner name from the received response (S1506, S504). The job owner name is determined, for example, by referring to the username in the user information list that has been registered in the MFP in advance. If there is a matching username, it is determined that the job owner is a regular user; otherwise, it is determined to be a guest user.
[0045] If the user is a guest user, S503 determines from the response received whether a PIN is set for the received print job (S508). The determination of whether a PIN is set is made by checking, for example, the presence or absence of the job-password attribute in the received job data, as shown in Figure 6D. If a PIN is not set, the acquisition of the print job data is canceled (S1507, S509). For example, if print job data has already been received, that print job data is discarded. Then, an "Update-job-status" message is sent to CPS102 to notify it of a job status error, as shown in Figure 6(F) (S1508, S510).
[0046] If it is determined in S504 that the user is a legitimate user, or if a PIN has been set in S508, the CPU of the printer 101 retrieves the corresponding print job data from the CPS 102 (S505). The retrieved print job data is then saved to the printer 101's own storage (S1509, S506). The CPU of the printer 101 then sends an "Update-job-status" message to the CPS 102 to notify it of the job's success, as shown in Figure 6(E) (S1510, S507).
[0047] As a result, the printer 101 stores print job data of registered legitimate users or PIN-configured print job data of guest users, and no other print job data is stored. The procedure for printing will now be explained with reference to example screens displayed on the user interface of the printer 101.
[0048] The user logs in as a guest user by entering their username (user ID) and the password registered as user information associated with the username on the login screen shown in Figure 3(A), or by touching the guest login button (S1511). Depending on the user, if the logged-in user is a regular user, the job list screen shown in Figure 3(B) is displayed, and if the logged-in user is a guest user, the job list screen shown in Figure 3(C) is displayed. In this embodiment, since the print jobs to be executed by the printing device 101 that have been fed into the CPS102 have already been acquired, the job list displays the print jobs of the logged-in user from among the print jobs acquired from the CPS102. If the user is logged in as a guest user, the list displays the print jobs of the guest user in the CPS102.
[0049] When a job is selected from the displayed job list screen (S1512), the printer 101 displays the PIN input screen shown in Figure 3(F) if the selected job is a print job for which a PIN has been set (S1513). Note that in Figure 3, the transition to Figure 3(F) is shown only from the guest user's print job list in Figure 3(C), but if a job is for which a PIN has been set, the transition to Figure 3(F) may be made from the list screen in Figure 3(B). When the user enters a PIN on that screen (S1514), the PIN set for that print job and the entered PIN are compared and verified (S1515).
[0050] If verification is successful, printing will proceed (S1516); if it fails, the screen shown in Figure 3(G) indicating that PIN verification failed will be displayed and printing will be canceled (S1517). Even though printing is canceled, printing has not yet started at this stage, so a message indicating that PIN verification failed will be output, and the system will return to S1513 to wait for PIN input again. Alternatively, the system may return to S1512 to redisplay the job list screen and resume processing from the selection of a print job. On the other hand, if PIN verification is successful, or if the print job for which a print command has been issued does not have a PIN set, printing may be performed. During printing, the printing screen shown in Figure 3(D) will be displayed, and when printing is complete, the print completion screen shown in Figure 3(E) will be displayed. In this embodiment, the printer 101 will not execute a print job for a guest user that does not have a PIN set from the CPS 102, so there is no direct transition from Figure 3(C) to Figure 3(D). This is the same in other embodiments.
[0051] In this embodiment, print jobs where the owner is a guest user and no PIN is specified will result in an error. This ensures security even for print jobs created by guest users.
[0052] Although print job data is acquired in step S505, if the print job acquisition response received in S503 contains print job data, it is not necessary to acquire it again in S505. In that case, in S505, the print job data already received in S503 and stored in the printing device 101 is acquired.
[0053] <Second Embodiment> In the second embodiment, we will describe the case in S1501 to S1503 of Figure 15 where the client terminal sends a print job to the CPS102, the CPS102 sends a job event notification to the printing device 101, and then the job is acquired upon login. The hardware configuration of each device in the second embodiment is the same as in the first embodiment. The differences from the first embodiment will be described below.
[0054] When a user logs in to the printer 101 (S1518), the printer 101 sends a request to retrieve the job list (S1519), and in response, receives and retrieves the logged-in user's job list information from the CPS 102 (S1520). The printer 101 displays the job list based on the retrieved job list information (S1521), and the user selects the target print job from there (S1522).
[0055] The processing procedure by the printing device 101 of this embodiment, as shown in Figure 7, represents the procedure after the user has logged in, i.e., after the processing up to S1522 has been completed.
[0056] First, the CPU of the printing device 101 detects that printing of the job has been selected (S701). Steps S702 to S704 are the same as the flow from S502 to S504 in the first embodiment.
[0057] In S704, the printer 101 determines whether the logged-in user is a registered regular user or a guest user. If the logged-in user is a regular user, the printer 101 determines whether a PIN is set for the target print job (S704-2). If no PIN is set, it retrieves the print job obtained in S705 and prints it (S1532, S706). The CPU of the printer 101 then sends a job status success notification to the CPS 102 (S707). If it is determined that a PIN is set, the process branches to S709 to verify the PIN.
[0058] If the logged-in user is a guest user, the system determines whether a PIN is set based on the response received in S703, similar to S508 (S1525, S708). If a PIN is not set, the acquisition of print job data is canceled, similar to S509 (S1526, S711). Then, a job status error is notified to CPS102, similar to S510 (S1527, S712).
[0059] If a PIN is set, the PIN input screen is displayed (S709). Then, the entered PIN is verified (S710). If the PIN matches, the process continues to S706. If it does not match, the process continues to S711.
[0060] In this embodiment, by making jobs where the user is a guest user and no PIN is specified an error, it is possible to prevent other guest users from printing, thereby ensuring security.
[0061] In this embodiment, print jobs where the owner is a guest user and no PIN is specified are flagged as errors. This ensures security for guest user print jobs as well. Furthermore, in this embodiment, the process of flagging print jobs where the owner is a guest user and no PIN is specified is performed after the guest user logs in, so the result of this process can be notified to the guest user. As a result, the guest user can find out that they failed to retrieve the print job because they did not set a PIN, and can then upload a print job with a PIN set to CPS102.
[0062] <Third Embodiment> In the third embodiment, we will describe the case in which the printer 101 registers its capabilities as a Preset with a guest user and PIN setting. Figure 8 shows an example of the processing procedure when registering the printer 101 with the CPS 102. The processing in Figure 8 should be executed before the printer information notification (S1602) in Figure 13A.
[0063] The printing device 101 generates its own capability information (S801). An example of capability information is shown in Figure 9. Figure 9(A) shows an example of capability information generated by a printing device that cannot print by a guest user, and Figure 9(B) shows an example of capability information generated by a printing device that can print by a guest user. In S801, regardless of whether or not a guest user can print, the capability information shown in Figure 9(A) is created first. This includes information about basic printing capabilities such as copies / sides / number-up.
[0064] Next, it is determined whether guest printing is possible (S802). The determination of whether guest printing is possible can be made by setting a "guest printing enabled setting" on the printing device and following that setting, or by obtaining a setting policy from an external terminal such as the cloud and following that. In this embodiment, the printing device 101 also needs to support PIN printing, so the determination of whether guest printing is possible can be made if the "guest printing enabled setting" of the printing device is set to "enabled" and PIN printing is supported. Of course, if the presence or absence of PIN printing support was determined when the "guest printing enabled setting" was set, it is not necessary to determine it here.
[0065] If guest printing is not possible, the CPU of the printer 101 sends the generated capability information (the information exemplified in Figure 9(A)) to the CPS 102 (S803). If guest printing is possible, the guest user's print preset information is added to the capability information generated in S801, as shown in Figure 9(B) (S804). Preset information refers to job-presets-supported, as shown in Figure 9(B). A preset is a collection of pre-configured items and their values. In this example, the preset name, pass-third encryption method, and account type are included in the preset information. Figure 9(B) shows preset information named preset1, which specifies that if the account type is guest, a PIN encrypted with sha2-256 hash should be used.
[0066] The CPU of the printing device 101 then transmits the added capability information to the CPS 102 (S803).
[0067] Printer information, including this capability information, is provided to client 103 via CPS102. Upon receiving this capability information, client 103 selects Preset1, which was received along with the capability information for printer 101. As shown in Figure 9(B), the settings of account type guest and predetermined PIN setting are applied. As a result, if a guest user selects printer 101 and selects Preset1 on client 103, they will be prompted to enter a PIN for the target print job. Once the PIN is entered, the print job is sent to CPS102.
[0068] By preparing presets with pre-configured PINs in this way, the likelihood of PIN settings being applied to guest users' print jobs increases, reducing the risk of printing to other guest users and ensuring security.
[0069] <Fourth Embodiment> In the fourth embodiment, we will describe a case in which, in client terminals 103 to 104, it is determined whether the user operating the client terminal is a regular user or a guest user, and if it is a guest user, PIN setting is made mandatory.
[0070] Figure 10 shows an example of the hardware configuration of a client terminal. Each component is omitted as it was explained in the first embodiment. Figure 12 shows an example of the user interface when printing on the client terminal 103.
[0071] In this embodiment, the process will be explained in accordance with the control flow in the client terminal's CPU shown in Figure 11. First, in S1101, the client terminal's CPU 1001 detects that the user has selected "Print" while an arbitrary document is open, as shown in Figure 12(B), and has selected the print settings display. Next, in S1102, the CPU 1001 determines whether the user who selected the print settings display is a regular user or a guest user of the cloud print service. One method for determining whether a user is a regular user or a guest user is to log in to the CPS 102 in advance by entering a username and password on the client terminal, as shown in Figure 12(A), and then determine if the user ID (user identification information) is that of a regular user. Users who are not regular users log in as guest users, so they can be identified using this method. Another method is to obtain usage rights for the CPS 102 using an account from another cloud ID service provider, as shown in Figure 12(A), and then determine if the user is a guest user. Alternatively, the user information can be sent to the CPS 102, and the system can determine whether the user is a regular user or a guest user by receiving a response from the CPS 102.
[0072] In S1102, if the CPU 1001 determines that the logged-in user is a legitimate user, in S1103, the CPU 1001 displays a print settings screen as shown in Figure 12(C). This print settings screen allows users to choose whether or not to set a PIN. The legitimate user sets their desired print settings and presses the "Print" button. In S1104, when the CPU 1001 detects that the "Print" button has been pressed, it generates print attribute information from the set print settings. Then, in S1105, the CPU 1001 sends the generated print attribute information and print data to the CPS 102. If a PIN is set, the "Job-password" and "Job-password-encryption" attributes are included in the print attribute information. If a PIN is not set, these attributes are not included.
[0073] Furthermore, if S1102 determines that the user is a guest user, CPU1001 displays a print settings screen in S1106 as shown in Figure 12(D). In these print settings, the PIN setting is a required input field. That is, the PIN setting is pre-set to "Use" and cannot be set to "Do not use". For example, a guest user cannot press the "Print" button without entering a PIN code. Alternatively, the screen is controlled to display an input error if the "Print" button is selected without entering a PIN code. The guest user enters the PIN code and presses the "Print" button.
[0074] In S1104, when the CPU detects that the print button has been pressed, it stores the PIN code information in the "Job-password" and "Job-password-encryption" attributes and generates print attribute information. Then, in S1105, the CPU 1001 sends the generated print attribute information and print data to the CPS 102. For guest users, the "Job-password" and "Job-password-encryption" attributes will always be included.
[0075] Furthermore, this embodiment assumes that the printer 101 has the capability to set a PIN. That is, when the client terminal creates a printer, it obtains capability information for the printer 101, and it is assumed that this information includes a capability attribute for setting a PIN, such as "Job-password-supported". For this reason, for example, before displaying the print settings screen in S1106, if the capability information for the selected printer does not include a PIN attribute, an error message indicating that printing is not possible with that printer may be output. Although Figure 12(E) shows an example of a screen displaying "Printing in Progress", for example, "Uploading in Progress" may be displayed instead of Figure 12(E) until the upload of the print job is complete. Alternatively, once the upload is complete, a message indicating completion may be displayed.
[0076] In this way, the client terminal controls the print settings screen to require PIN setting for guest users, ensuring that all guest user print jobs are always PIN-enabled. As a result, even if another guest user tries to print, they will not know the PIN code, thus making it impossible for other guest users to print and thus ensuring security.
[0077] <Fifth Embodiment> In the fifth embodiment, we will describe a case in which, when the CPS102 receives a print job from a client terminal, it determines whether the print job is from a guest user and, if the guest user has not set a PIN, performs control to add a PIN setting. An example of the hardware configuration of the CPS102 is the same as that of the client shown in Figure 10.
[0078] This embodiment will be explained following the control flow in the CPU 1301 of the CPS 102 shown in Figure 14. First, in S1401, the CPU 1301 detects the submission of a print job from a client terminal. Once the print job submission is detected, in S1402, the CPU 1301 determines whether the job owner of that print job is a regular user or a guest user of the CPS 102. One method of determination is to check whether the value of "Job-originating-user-uri" included in the print attribute information is included in the list of accounts managed by the CPS 102. Alternatively, even if the "Job-originating-user-uri" attribute is not used, other attribute information such as "Requesting-user-uri" or "Job-originating-user-name" may be used for determination if it is possible to make a determination. Or, even if it is not print attribute information, the user may be determined to be a regular user or a guest user by performing HTTP authentication or OAUTH authentication when a print job is submitted from the client terminal.
[0079] If the CPU 1301 determines in S1402 that the user is a legitimate user of CPS102, it stores the received print data and print attribute information in the CPS102's storage in S1403. Then, in S1404, it notifies the printing device 101 that the job has been received. This notification to the printing device 101 may be done using, for example, the IPP's Get-Notifications operation.
[0080] Furthermore, if S1402 determines that the user is a guest user of CPS102, CPU1301 determines in S1405 whether the received print attribute information includes PIN settings. The determination of whether PIN settings are included is made by checking for the presence or absence of attribute information related to PIN settings, such as "Job-password" and "Job-password-encryption". If it is determined that PIN settings are included, CPU1301 determines that there is no problem and proceeds to S1403.
[0081] On the other hand, if S1405 determines that it is a guest user's job and that no PIN has been set, CPU1301 adds a PIN in S1406. For example, CPU1301 randomly generates a PIN code, and from that, generates attribute information related to the PIN setting, such as "Job-password" and "Job-password-encryption," and adds it to the received print attribute information. In S1407, the CPU notifies the client terminal of the generated PIN code. The notification method can be any means that the guest user can recognize through the client terminal, such as email.
[0082] Note that for print jobs without a PIN setting, the printing device on which the print job will be executed may not necessarily support PIN settings. Therefore, before adding a PIN setting to the print job in S1406, it may be determined whether the printing device 101 on which the print job will be executed has the capability for PIN printing, and if it does, S1406 may be executed. If it is determined that the printing device 101 on which the print job will be executed does not have the capability for PIN printing, an error indicating this may be sent to the client terminal that sent the print job, and the print job may be discarded.
[0083] In this way, even if a client terminal receives a print job from a guest user without a PIN setting, the CPS102 will always add a PIN setting, ensuring that guest user print jobs are always PIN-set. Therefore, even if another guest user tries to print, they will not know the PIN code, making it impossible for other guest users to print, thus ensuring security.
[0084] In the embodiments described above, the printer 101 will not execute print jobs of guest users for whom a PIN, or password, has not been set. This is because the printer 101 will either cancel, or discard, the print jobs of guest users for whom a PIN has not been set, or the client terminal 013 or CPS012 will set a PIN for the guest user's print job. As a result, the print jobs of guest users executed by the printer 101 will be PIN-set, preventing or suppressing the execution of print jobs by users other than those for whom a PIN has been set.
[0085] ●Summary of Embodiments The above embodiment can be summarized as follows. [Item 1] A printing system comprising a printing device, a printing service system connected to the printing device, and an information processing device connected to the printing service system, The printing service system includes registration means for registering the printing device and storage means for storing print jobs received from the information processing device. The information processing device has a transmission means for transmitting a print job from a logged-in user to the print service system, specifying a print device selected from among the print devices registered in the print service system. The printing device includes storage means for storing users of the printing service system in association with users of the printing device, and printing means for retrieving print jobs of users associated with the logged-in user of the printing device from among the print jobs stored in the printing service system and executing printing. The guest users of the printing service system are linked to the guest users of the printing device. For print jobs of the aforementioned guest user for which no password has been set, printing will not be performed by the aforementioned printing device. A printing system characterized by the following features.
[0086] [Item 2] The printing system described in item 1, In the registration means, the capability information of the printing device is registered, and the capability information includes information indicating the capability of a printing device that has the capability to execute a password-protected print job. If the capability information of the printing device includes information indicating its ability to execute the print job for which the password has been set, then the print job can be password-protected. A printing system characterized by the following features.
[0087] [Item 3] A printing system as described in item 1 or 2, The printing device will cancel the print job of the guest user for whom the password is not set and will not perform printing. A printing system characterized by the following features.
[0088] [Item 4] The printing system described in item 3, The printing device, upon receiving notification from the printing service system that a print job has been sent from the information processing device, acquires the print job and cancels the print job of the guest user for whom no password has been set, and does not execute the print job. A printing system characterized by the following features.
[0089] [Item 5] The printing system described in item 3, The printing device retrieves the print jobs of the logged-in user in response to an operation by the logged-in user, and cancels print jobs where the logged-in user is the guest user and no password has been set, and does not execute the print job. A printing system characterized by the following features.
[0090] [Item 6] A printing system as described in item 4 or 5, When the printing device cancels the print job, it also outputs an error to the logged-in user. A printing system characterized by the following features.
[0091] [Item 7] A printing system as described in any one of items 1 to 6, The information processing device, if the logged-in user is the guest user, displays a user interface for setting a password for the print job and sends the print job with the password set to the print service system. A printing system characterized by the following features.
[0092] [Item 8] The printing system described in item 7, The information processing device obtains capability information of the selected printing device from the print service system and displays the user interface for setting a password for the print job if the printing device has the capability to execute the password-protected print job and the logged-in user is the guest user. A printing system characterized by the following features.
[0093] [Item 9] The printing system described in item 8, The information processing device obtains capability information of the selected printing device from the print service system and outputs an error message if the printing device does not have the capability to execute the print job for which the password has been set and the logged-in user is the guest user. A printing system characterized by the following features.
[0094] [Item 10] A printing system as described in any one of items 1 to 6, If the print job received from the information processing device is a print job for a guest user, the print service system sets a password for the print job and notifies the guest user of the set password. A printing system characterized by the following features.
[0095] [Item 11] The printing system described in item 10, The print service system sets a password for the print job if the capability information of the printing device selected for the print job indicates that the printing device is capable of executing the password-protected print job, and the print job belongs to the guest user. A printing system characterized by the following features.
[0096] [Item 12] The printing system described in item 11, The print service system discards the print job if the capability information of the printing device selected for the print job does not indicate that the printing device is capable of executing the password-protected print job. A printing system characterized by the following features.
[0097] [Item 13] A printing control method using a printing system that includes a printing device, a printing service system connected to the printing device, and an information processing device connected to the printing service system, The printing service system registers the printing device and stores the print jobs received from the information processing device. The information processing device sends a print job from a logged-in user to the print service system, specifying a print device selected from among the print devices registered in the print service system. The printing device registers users of the printing service system in association with users of the printing device, retrieves print jobs of users associated with the logged-in user of the printing device from among the print jobs stored in the printing service system, and executes printing. The guest users of the printing service system are linked to the guest users of the printing device. For the aforementioned guest user's print job, if no password is set, or if a password cannot be set, printing will not be executed. A printing control method characterized by the following:
[0098] [Other examples] The present invention can also be realized by supplying a program that implements one or more of the functions of the above-described embodiments to a system or device via a network or storage medium, and by having one or more processors in the computer of that system or device read and execute the program. It can also be realized by a circuit (e.g., an ASIC) that implements one or more functions.
[0099] The invention is not limited to the embodiments described above, and various modifications and variations are possible without departing from the spirit and scope of the invention. Accordingly, claims are attached to disclose the scope of the invention. [Explanation of Symbols]
[0100] 101 Printing device, 102 Cloud print service, 103 Client terminal, 104 Client terminal
Claims
1. A printing system comprising a printing device, a printing service system connected to the printing device, and an information processing device connected to the printing service system, The printing service system includes registration means for registering the printing device and storage means for storing print jobs received from the information processing device. The information processing device has a transmission means for transmitting a print job from a logged-in user to the print service system, specifying a print device selected from among the print devices registered in the print service system. The printing device includes storage means for storing users of the printing service system in association with users of the printing device, and printing means for retrieving print jobs of users associated with the logged-in user of the printing device from among the print jobs stored in the printing service system and executing printing. The guest users of the printing service system are linked to the guest users of the printing device. For print jobs of the guest user for whom no password is set, the printing device cancels the print job of the guest user for whom no password is set and does not perform printing. A printing system characterized by the following features.
2. A printing system according to claim 1, In the registration means, the capability information of the printing device is registered, and the capability information includes information indicating the capability of a printing device that has the capability to execute a password-protected print job. If the capability information of the printing device includes information indicating its ability to execute the print job for which the password has been set, then the print job can be password-protected. A printing system characterized by the following features.
3. A printing system according to claim 1, The printing device, upon receiving notification from the printing service system that a print job has been sent from the information processing device, acquires the print job and cancels the print job of the guest user for whom no password has been set, and does not execute the print job. A printing system characterized by the following features.
4. A printing system according to claim 1, The printing device retrieves the print jobs of the logged-in user in response to an operation by the logged-in user, and cancels print jobs where the logged-in user is the guest user and no password has been set, and does not execute the print job. A printing system characterized by the following features.
5. A printing system according to claim 3, When the printing device cancels the print job, it also outputs an error to the logged-in user. A printing system characterized by the following features.
6. A printing system according to claim 1 or 2, The information processing device, if the logged-in user is the guest user, displays a user interface for setting a password for the print job and sends the print job with the password set to the print service system. A printing system characterized by the following features.
7. A printing system according to claim 6, The information processing device obtains capability information of the selected printing device from the print service system and displays the user interface for setting a password for the print job if the printing device has the capability to execute the password-protected print job and the logged-in user is the guest user. A printing system characterized by the following features.
8. A printing system according to claim 7, The information processing device obtains capability information of the selected printing device from the print service system and outputs an error message if the printing device does not have the capability to execute the print job for which the password has been set and the logged-in user is the guest user. A printing system characterized by the following features.
9. A printing system according to claim 1 or 2, If the print job received from the information processing device is a print job for a guest user, the print service system sets a password for the print job and notifies the guest user of the set password. A printing system characterized by the following features.
10. A printing system according to claim 9, The print service system sets a password for the print job if the capability information of the printing device selected for the print job indicates that the printing device is capable of executing the password-protected print job, and the print job belongs to the guest user. A printing system characterized by the following features.
11. A printing system according to claim 10, The print service system discards the print job if the capability information of the printing device selected for the print job does not indicate that the printing device is capable of executing the password-protected print job. A printing system characterized by the following features.
12. A printing control method using a printing system that includes a printing device, a printing service system connected to the printing device, and an information processing device connected to the printing service system, The printing service system registers the printing device and stores the print jobs received from the information processing device. The information processing device sends a print job from a logged-in user to the print service system, specifying a print device selected from among the print devices registered in the print service system. The printing device registers users of the printing service system in association with users of the printing device, retrieves print jobs of users associated with the logged-in user of the printing device from among the print jobs stored in the printing service system, and executes printing. The guest users of the printing service system are linked to the guest users of the printing device. For print jobs of the guest user for whom no password is set, the printing device cancels the print job of the guest user for whom no password is set and does not perform printing. A printing control method characterized by the following: