Monitoring device, its control method and program

JP7899065B2Active Publication Date: 2026-08-03CANON KK
View PDF 6 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
CANON KK
Filing Date
2022-11-21
Publication Date
2026-08-03

AI Technical Summary

Benefits of technology

【0006】 一部の実施形態によれば、デバイスによる外部サーバとの通信を監視装置が監視できるようになる。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007899065000001
    Figure 0007899065000001
  • Figure 0007899065000002
    Figure 0007899065000002
  • Figure 0007899065000003
    Figure 0007899065000003
Patent Text Reader

Abstract

To provide a technique for allowing a monitoring apparatus to monitor the communication with an external server by a device.SOLUTION: A monitoring apparatus for monitoring a device includes: an acquisition unit that acquires a device list from a device management server, a determination unit that determines a monitoring method for monitoring devices included in the device list; and a registration processing unit that executes a first registration process to register a first device monitored by a first monitoring method with an authorization server and a second registration process different from the first registration process to register a second device monitored by a second monitoring method different from the first monitoring method with the authorization server. The first registration process includes instructing the first device to use a designated proxy server, and instructing the first device to send a request to the authorization server requesting that the first device be registered with the authorization server, after the first device begins using the designated proxy server.SELECTED DRAWING: Figure 13
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a monitoring device, a control method thereof, and a program.

Background Art

[0002] By utilizing information from various devices connected to a server through a network, a mechanism called Internet of Things (IoT) that provides high-value-added services has been realized. IoT can include two systems. One is a device management system that provides a device management service for managing connected devices, a storage service for managing the collected device information, an authorization service having an authorization function for securely connecting a device to a cloud service, and the like. The other is a contract service providing system that cooperates with the device management system and provides various services such as device maintenance services and reporting services. Patent Document 1 proposes a system in which a device having a self-registration function performs a registration process in place of another device having a self-registration function and delegates the acquired authority.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] In Patent Document 1, a device registered in an authorization server uses the services of this server by directly communicating with an external server on the Internet. However, the free communication of a device with an external server may cause security concerns. Some aspects of the present invention aim to provide a technique for enabling a monitoring device to monitor the communication between a device and an external server. [Means for solving the problem]

[0005] According to some embodiments, a monitoring device is provided, comprising: acquisition means for obtaining a device list from a device management server; determination means for determining a monitoring method for monitoring devices included in the device list; and registration processing means for executing a first registration process to register a first device monitored by a first monitoring method with an authorization server, and executing a second registration process different from the first registration process to register a second device monitored by a second monitoring method different from the first monitoring method with the authorization server, wherein the first registration process includes instructing the first device to use a designated proxy server, and, after the first device has started using the designated proxy server, instructing the first device to send a request to the authorization server requesting that the first device be registered with the authorization server. [Effects of the Invention]

[0006] According to some embodiments, a monitoring device can monitor communication between a device and an external server. [Brief explanation of the drawing]

[0007] [Figure 1] A block diagram illustrating an example of a network configuration including a management system according to the first embodiment. [Figure 2] A block diagram illustrating an example of the hardware configuration of an image forming apparatus according to the first embodiment. [Figure 3] A block diagram illustrating an example of the hardware configuration of a computer according to the first embodiment. [Figure 4] A block diagram illustrating an example of the software configuration of an image forming apparatus according to the first embodiment. [Figure 5] A block diagram illustrating an example of the software configuration of a monitoring device according to the first embodiment. [Figure 6] A diagram illustrating the information managed by the device management server according to the first embodiment. [Figure 7] A diagram illustrating the information managed by the monitoring device according to the first embodiment. [Figure 8] A diagram illustrating the information managed by the authorization server according to the first embodiment. [Figure 9] A sequence diagram illustrating an example of registration processing for a monitoring device and an image forming apparatus according to the first embodiment. [Figure 10] A schematic diagram illustrating an example of a screen for obtaining instructions for the registration process according to the first embodiment. [Figure 11] A schematic diagram illustrating an example screen for displaying tenant information according to the first embodiment. [Figure 12] A sequence diagram illustrating an example of the self-registration process of a monitoring device according to the first embodiment. [Figure 13] A sequence diagram illustrating an example of the registration process of an image forming apparatus according to the first embodiment. [Figure 14] A schematic diagram illustrating an example screen for obtaining the settings of the monitoring method according to the first embodiment. [Figure 15] A sequence diagram illustrating an example of self-registration processing in an image forming apparatus according to the first embodiment. [Figure 16] A flowchart illustrating an example of the registration status confirmation process according to the first embodiment. [Figure 17] A sequence diagram illustrating an example of an alternative registration process for an image forming apparatus according to the first embodiment. [Figure 18] A sequence diagram illustrating an example of self-registration processing in an image forming apparatus according to the second embodiment. [Modes for carrying out the invention]

[0008] The embodiments will be described in detail below with reference to the attached drawings. Note that the following embodiments do not limit the invention as defined in the claims. While the embodiments describe multiple features, not all of these features are essential to the invention, and the features may be combined in any way. Furthermore, in the attached drawings, identical or similar configurations are given the same reference numerals, and redundant descriptions are omitted.

[0009] <First Embodiment> [Network Configuration] Referring to FIG. 1, a network configuration example including a management system 100 according to the first embodiment will be described. The management system 100 manages one or more devices. In the first embodiment, as an example of a device managed by the management system 100, an image forming apparatus 102 is handled. Instead of or in addition to the image forming apparatus 102, the management system 100 may manage other devices such as home appliances, lighting devices, air conditioning devices, sensors, etc. When the management system 100 manages other devices, the image forming apparatus 102 in the following description is replaced with other devices. In FIG. 1, three image forming apparatuses 102 connected to the same local area network (LAN) 121 are shown as devices managed by the management system 100. Instead of this, the management system 100 may manage other numbers of devices or may manage devices distributed over a plurality of LANs.

[0010] The management system 100 includes a device management server 111, an authorization server 112, a resource server 113, a service providing server 114, and an access destination management server 115. Each server may be realized by providing the functions of each of those servers as services as an application server on one or more server computers. Also, it may operate as an application server on a virtual machine using hardware resources on one or more computers. Instead of this, the management system 100 may be considered to be constituted by only a part of these components or may include other components.

[0011] The monitoring device 101 is connected to the same LAN 121 as the image forming apparatus 102 to be managed. The management system 100 is connected to a network 122 different from the LAN 121. The monitoring device 101 can communicate with servers (such as the device management server 111) in the management system 100 through a wide area network 120 such as the Internet.

[0012] Alternatively, at least one of the plurality of servers within the management system 100 may be connected to the LAN 121. The plurality of servers within the management system 100 may be distributed and arranged across a plurality of LANs. At least one of the plurality of servers within the management system 100 may be arranged on the cloud.

[0013] The monitoring device 101 monitors the image forming device 102 to be managed. For example, the monitoring device 101 collects information from the image forming device 102. The servers within the management system 100 manage the information collected by the monitoring device 101 and the image forming device 102 to be managed, and provide various services. The device management server 111 manages the information of the monitoring device **********

[0014] The authorization server 112 provides an authorization service for securely connecting the monitoring device 101 and the image forming device 102 to other servers within the management system 100. In the authorization service, an authorization process is performed. The authorization server 112 may provide the authorization service using the OAuth mechanism. The authorization server 112 registers the monitoring device 101 and the image forming device 102 with itself as clients associated with a specific tenant. A tenant is an administrative unit assigned to each customer who has entered into a service usage contract. The authorization server 112 manages data on a tenant-by-tenan**********

[0015] The resource server 113 manages information collected from the image forming apparatus 102. The information managed by the resource server 113 may be used to provide services. The access destination management server 115 provides the URL (Uniform Resource Locator) of the server to which each device accesses (e.g., the device management server 111 or the resource server 113) in response to requests from the monitoring device 101 and the image forming apparatus 102. The service provision server 114 uses the information of the image forming apparatus 102 managed by the resource server 113 to provide services such as maintenance services and reporting services. The service provision server 114 may provide the user with a web user interface (UI) for configuring information on the monitored device 101 and the image forming apparatus 102 under management.

[0016] [Hardware configuration of image forming apparatus] Referring to Figure 2, an example of the hardware configuration of the image forming apparatus 102 will be described. The image forming apparatus 102 may include the components shown in Figure 2. The image forming apparatus 102 may not include some of the components shown in Figure 2, or it may include components not shown in Figure 2.

[0017] The central processing unit (CPU) 201 comprehensively controls each device connected to the system bus 206 by executing software stored in the read-only memory (ROM) 202 or the hard disk drive (HDD) 205. The random access memory (RAM) 203 functions as a work area for the CPU 201, etc. The hard disk controller (HDC) 204 controls reading and writing to the HDD 205.

[0018] The reader interface (I / F) 207 is connected to the reader unit 212. The reader I / F 207 controls the reader unit 212. The printer I / F 208 is connected to the printer unit 213. The printer I / F 208 controls the printer unit 213. The operation I / F 209 is connected to the operation unit 214. The operation I / F 209 controls the display on the operation unit 214 and user input from the operation unit 214. The operation unit 214 consists of, for example, buttons for operation and a display unit. The switch I / F 210 is connected to the switch unit 215. The switch I / F 210 controls operations from the switch unit 215. The switch unit 215 consists of switches for operation, etc. The network I / F 211 exchanges data with external devices such as a host computer via the LAN 121.

[0019] In Figure 2, the area enclosed by the dashed line represents the control unit 200. The control unit 200 controls various devices and interfaces connected to the image forming apparatus 102, and controls the operation of the entire image forming apparatus 102. The reader unit 212 reads the image of the original document and, according to instructions from the user, outputs the image data representing that image to the printer unit 213 or stores it in the HDD 205. The reader unit 212 may also transmit the image data to a host computer connected to the LAN 121 via the network I / F 211. The printer unit 213 prints the original document read by the reader unit 212 or the image data stored in the HDD 205. The printer unit 213 may also receive print jobs from a host computer connected to the LAN 121 via the network I / F 211 and print them.

[0020] [Computer hardware configuration] Referring to Figure 3, an example of the hardware configuration of computer 300 will be described. Computer 300 may include the components shown in Figure 3. Computer 300 may not include some of the components shown in Figure 3, or it may include components not shown in Figure 3. Computer 300 may be used as either a monitoring device 101 or a server in the management system 100 (for example, a device management server 111).

[0021] The CPU 301 reads a program from the storage device 303 into memory 302 and executes the program. The CPU 301 is an example of a general-purpose processor. Memory 302 may be composed of RAM, for example. The storage device 303 stores the OS (Operating System), application programs, data, etc. The storage device 303 may be composed of HDD, for example. The output I / F 304 is an interface for connecting output devices such as displays. The output I / F 304 outputs the execution results of programs, etc., to the output device. The input I / F 305 is an interface for connecting input devices such as keyboards and pointing devices. The input I / F 305 obtains user input from the input device. The communication I / F 306 is a network interface for communicating with external systems and devices.

[0022] [Software configuration of image forming apparatus] Referring to Figure 4, an example of the software configuration of the image forming apparatus 102 will be described. The image forming apparatus 102 may include the components shown in Figure 4. The image forming apparatus 102 may not include some of the components shown in Figure 4, or it may include components not shown in Figure 4. Each component of the image forming apparatus 102 may be realized, for example, by the CPU 201 of the image forming apparatus 102 executing a program loaded into the RAM 203. The functions of the components of the image forming apparatus 102 will be described in more detail later with reference to sequence diagrams and flow diagrams.

[0023] The authorization processing unit 401 performs self-registration processing with the authorization server 112, and acquires and manages tokens. Self-registration processing with the authorization server 112 refers to the process of registering itself (for example, the image forming apparatus 102; may also be referred to as "the apparatus") with the authorization server 112 as a client. Self-registration processing may include sending a request to the authorization server 112 asking to register itself (for example, the image forming apparatus 102) with the authorization server 112. The authorization processing unit 401 may communicate with the monitoring device 101 to configure settings used for monitoring the image forming apparatus 102.

[0024] The data management unit 402 manages data such as proxy server settings. The data acquisition unit 403 collects data from the components of the image forming apparatus 102 for transmission to the resource server 113. The data transmission unit 404 transmits the data collected by the data acquisition unit 403 to the resource server 113.

[0025] Some of the multiple image forming machines 102 managed by the management system 100 do not need to include the authorization processing unit 401. Image forming machines 102 that do not include the authorization processing unit 401 cannot perform self-registration processing. Therefore, as will be described later, the monitoring device 101 registers the image forming machines 102 with the authorization server 112 on behalf of the image forming machines 102.

[0026] [Software configuration of monitoring device] Referring to Figure 5, an example of the software configuration of the monitoring device 101 will be described. The monitoring device 101 may include the components shown in Figure 5. The monitoring device 101 may not include some of the components shown in Figure 5, or it may include components not shown in Figure 5. Each component of the monitoring device 101 may be realized, for example, by the CPU 301 of the computer 300 operating as the monitoring device 101 executing a program loaded into memory 302. The functions of the components of the monitoring device 101 will be described in more detail later with reference to sequence diagrams and flow diagrams.

[0027] The device management unit 501 manages the image forming apparatus 102 managed by the management system 100. For example, the device management unit 501 manages the image forming apparatus 102 connected to the same LAN 121. Specifically, the device management unit 501 may instruct the image forming apparatus 102 to configure the proxy server, register the monitoring device 101 and the image forming apparatus 102 with the authorization server 112, or manage tokens issued by the authorization server 112.

[0028] The proxy unit 502 operates the monitoring device 101 as a proxy server. For example, the proxy unit 502 may operate the monitoring device 101 as a proxy server for the image forming apparatus 102. This causes communication from the image forming apparatus 102 to be aggregated at the monitoring device 101. Instead of operating the monitoring device 101 as a proxy server, the proxy unit 502 may operate another device connected to the LAN 121 as a proxy server. In this case, the proxy unit 502 may obtain communication data between the image forming apparatus 102 and the server in the management system 100 from the other device operating as a proxy server. A multi-stage proxy may be configured by placing other proxy servers in the communication path between the proxy server provided by the proxy unit 502 and the wide area network 120.

[0029] The monitoring device 101, acting as a proxy server, receives data that the image forming apparatus 102 transmits to an external device (for example, a server within the management system 100) via the wide-area network 120, and transmits this data to the external device on behalf of the image forming apparatus 102. Furthermore, the monitoring device 101, acting as a proxy server, receives data transmitted from the external device to the image forming apparatus 102 via the wide-area network 120, and transmits this data to the image forming apparatus 102.

[0030] The data management unit 503 manages information for monitoring the image forming apparatus 102. This information may include, for example, status information indicating whether the image forming apparatus 102 is under its management. The task management unit 504 manages various tasks such as self-registration processing of the monitoring device 101, monitoring and registration of the image forming apparatus 102. The screen control unit 505 outputs the screen to the output device via the output I / F 304 and acquires input information from the input device via the input I / F 305. The screen control unit 505 supplies the acquired input information to a component that processes this information (for example, the data management unit 503).

[0031] [Information managed by the device management server] Refer to Figure 6 to explain the information managed by the device management server 111. In the example in Figure 6, the device management server 111 manages the information in a table format. Alternatively, the device management server 111 may manage the information in another format. The device management server 111 manages the agent management table 600 and the device management table 610. These tables may be stored in the storage device 303 of the computer 300 operating as the device management server 111.

[0032] The agent management table 600 is a table for managing information about the monitoring device 101. The monitoring device 101 can register the image forming apparatus 102 with the authorization server 112 as a substitute for the image forming apparatus 102. Therefore, the monitoring device 101 may also be called an agent. The agent management table 600 may not include some of the columns shown in Figure 6, and may include columns not shown in Figure 6. Similarly, other tables described later may not include some of the illustrated columns, and may include columns not shown.

[0033] Agent ID 601 is information that uniquely identifies the monitoring device 101 in the management system 100. Agent ID 601 may be assigned to the monitoring device 101 by the device management server 111. Tenant ID 602 ​​is information that uniquely identifies the tenant to which the monitoring device 101 identified by Agent ID 601 belongs. Tenant ID 602 ​​may be assigned to the tenant by a server (not shown) that manages the tenant. Customer ID 603 is information that uniquely identifies the customer within the tenant identified by Tenant ID 602. Customer ID 603 may be assigned to the customer by a server (not shown) that manages the tenant. Tenant name 604 is the name of the tenant identified by Tenant ID 602. Tenant name 604 may be determined by the tenant's customers.

[0034] Client ID 605 is information that uniquely identifies a client of the authorization server 112 in the management system 100. A client of the authorization server 112 is an entity registered with the authorization server 112. In the first embodiment, the monitoring device 101 and the image forming apparatus 102 can each be clients of the authorization server 112. Client ID 605 may be assigned to a client by the authorization server 112.

[0035] The device management table 610 is a table for managing information about the image forming apparatus 102. The server-assigned device ID 611 is information that uniquely identifies the image forming apparatus 102 in the management system 100. The server-assigned device ID 611 may be assigned to the image forming apparatus 102 by the device management server 111. The serial number 612 is a number uniquely assigned to the image forming apparatus 102 by its manufacturer. The tenant ID 613 is information that uniquely identifies the tenant to which the image forming apparatus 102, identified by the server-assigned device ID 611, belongs. The tenant ID 613 has the same code system as the tenant ID 602. The agent ID 614 is information that uniquely identifies the monitoring device 101 associated with the image forming apparatus 102, identified by the server-assigned device ID 611. The agent ID 614 has the same code system as the agent ID 601.

[0036] The device management server 111 may add new records to the agent management table 600 and the device management table 610 in response to instructions from the service provision server 114. The service provision server 114 may obtain information on the monitoring device 101 and the image forming apparatus 102 managed by the management system 100 from the user via a web user interface, or from other devices via a web API.

[0037] [Information managed by monitoring devices] Referring to Figure 7, the information managed by the monitoring device 101 will be described. In the example in Figure 7, the monitoring device 101 manages the information in a table format. Alternatively, the monitoring device 101 may manage the information in another format. The monitoring device 101 manages a device management table 700. This table may be stored in the storage device 303 of the computer 300 operating as the monitoring device 101.

[0038] The device management table 700 is a table for managing information about the image forming apparatus 102. The monitoring device 101 adds a new record to the device management table 700 each time it acquires information about the image forming apparatus 102. Information about the image forming apparatus 102 is obtained, for example, from the device management server 111 as a list of devices to be managed. Devices to be managed are devices that the management device 101 should monitor.

[0039] Device ID 701 is information that uniquely identifies the image forming apparatus 102 in the monitoring device 101. Device ID 701 may be assigned to the image forming apparatus 102 by the monitoring device 101. Serial number 702 is a number uniquely assigned to the image forming apparatus 102 by its manufacturer. Internet Protocol (IP) address 703 is the IP address of the image forming apparatus 102 identified by device ID 701.

[0040] The management status 704 indicates whether the image forming apparatus 102 identified by device ID 701 is managed by the management system 100. An image forming apparatus 102 with a management status 704 of "Target" is subject to management by the management system 100. An image forming apparatus 102 with a management status 704 of "Not Target" is not subject to management by the management system 100.

[0041] The registration status 705 indicates whether the image forming apparatus 102 identified by device ID 701 is registered with the authorization server 112. An image forming apparatus 102 with a registration status 705 of "Registered" is registered with the authorization server 112. An image forming apparatus 102 registered with the authorization server 112 may be considered to be an image forming apparatus 102 registered with the management system 100. An image forming apparatus 102 with a registration status 705 of "Not Registered" is not registered with the authorization server 112. An image forming apparatus 102 with a registration status 705 of "Not Registered" may have been registered with the authorization server 112 in the past, or may have never been registered with the authorization server 112.

[0042] Monitoring method 706 indicates the monitoring method for the image forming apparatus 102 identified by device ID 701. An image forming apparatus 102 for which monitoring method 706 is "proxy" is monitored by monitoring device 101 using the proxy method. The proxy method is a method in which the image forming apparatus 102 communicates with a server through a proxy server, and the monitoring device 101 monitors the communication data transmitted or received by the image forming apparatus 102 through this proxy server. An image forming apparatus 102 for which monitoring method 706 is "polling" is monitored by monitoring device 101 using the polling method. The polling method is a method in which the monitoring device 101 monitors information acquired from the image forming apparatus 102 by polling.

[0043] Server-assigned device ID 707 is a server-assigned device ID assigned to the image forming apparatus 102 identified by device ID 701. Server-assigned device ID 707 has the same code system as server-assigned device ID 611.

[0044] [Information managed by the authorization server] Refer to Figure 8 to illustrate the information managed by the authorization server 112. In the example in Figure 8, the authorization server 112 manages the information in a table format. Alternatively, the authorization server 112 may manage the information in other formats. The authorization server 112 manages the agent activation code management table 800, the device activation code management table 810, the registration key management table 820, the client management table 830, and the credential management table 840. These tables may be stored in the storage device 303 of the computer 300 operating as the authorization server 112.

[0045] The agent activation code management table 800 is a table for managing activation codes related to the monitoring device 101. The authorization server 112 adds a new record to the agent activation code management table 800 each time it issues an activation code for the monitoring device 101.

[0046] Activation code 801 is an activation code issued by authorization server 112 for monitoring device 101. Activation codes may be issued on a per-monitoring device 101 basis. Agent ID 802 is the agent ID of monitoring device 101 to which activation code 801 was issued. Agent ID 802 has the same coding scheme as agent ID 601. Customer ID 803 is information that uniquely identifies the customer of the tenant to which monitoring device 101, identified by agent ID 802, belongs. Customer ID 803 has the same coding scheme as customer ID 603. Expiration date 804 is the expiration date set for activation code 801.

[0047] The device activation code management table 810 is a table for managing activation codes related to the image forming apparatus 102. The authorization server 112 adds a new record to the device activation code management table 810 each time it issues an activation code for the image forming apparatus 102.

[0048] Activation code 811 is an activation code issued by the authorization server 112 for the image forming apparatus 102. Activation codes may be issued on a per-image forming apparatus 102 basis. Serial number 812 is a number uniquely assigned to the image forming apparatus 102 by the manufacturer of the image forming apparatus 102 to which activation code 811 was issued. Device registration key 813 is the device registration key used to issue activation code 811. Expiration date 814 is the expiration date set for activation code 811.

[0049] The registration key management table 820 is a table for managing device registration keys. The authorization server 112 adds a new record to the registration key management table 820 each time it issues a device registration key.

[0050] The device registration key 821 is a device registration key issued by the authorization server 112. The device registration key may be issued on a per-tenant basis. Alternatively, the device registration key may be issued on a per-image forming apparatus 102 basis. The tenant ID 822 is information that uniquely identifies the tenant to which the device registration key 821 was issued. The tenant ID 822 has the same code system as the tenant ID 602. The expiration date 823 is the expiration date set for the device registration key 821.

[0051] The client management table 830 is a table for managing information about clients, namely the monitoring device 101 and the image forming apparatus 102. The client ID 831 is information that uniquely identifies the client of the authorization server 112 in the management system 100. When the client is the monitoring device 101, the client ID 831 may be the agent ID of the monitoring device 101. When the client is the image forming apparatus 102, the client ID 831 may be the server-assigned device ID of the image forming apparatus 102. The client ID 831 has the same code system as the client ID 605.

[0052] Serial number 832 is a number uniquely assigned to the image forming apparatus 102 by its manufacturer. Serial number 832 may be blank if the client is the monitoring device 101. Tenant ID 833 is information that uniquely identifies the tenant to which the client identified by client ID 831 belongs. Tenant ID 833 has the same coding scheme as tenant ID 602.

[0053] The authorization server 112 may add a new record to the client management table 830 in response to instructions from the service provision server 114. The authorization server 112 may obtain information about the monitoring device 101 and the image forming apparatus 102 managed by the management system 100 from the user via the web user interface, or from other devices via the web API.

[0054] The credential management table 840 is a table for managing credentials issued to clients, namely the monitoring device 101 and the image forming apparatus 102. The authorization server 112 adds a new record to the credential management table 840 each time it issues credentials.

[0055] Client ID 841 is information that uniquely identifies a client of the authorization server 112 in the management system 100. Client ID 841 has the same coding scheme as Client ID 831. Credential 842 is the credentials (e.g., a private key) issued to the client identified by Client ID 841. Credentials may be issued on a per-client basis.

[0056] [Registration process for monitoring devices and image forming devices] Referring to Figure 9, the registration process of the monitoring device 101 and the image forming apparatus 102 will be explained. The operations of each device and each server in this process may be realized by the CPU of each device and each server executing a program loaded into memory. Alternatively, some operations may be performed by dedicated circuits such as application-specific integrated circuits (ASICs). The same applies to the processes described in the drawings later.

[0057] In S901, the screen control unit 505 of the monitoring device 101 receives an instruction from the user 900 of the monitoring device 101 to start the registration process for the monitoring device 101 and the image forming apparatus 102. This instruction may include information used for the registration process. The information used for the registration process may include an agent ID and a customer ID. As described above, the agent ID is information that uniquely identifies the monitoring device 101 in the management system 100. As described above, the customer ID is information that uniquely identifies a customer within a tenant in the management system 100. Furthermore, the monitoring device 101 may receive information from the user 900 that is used for communication with the server in the management system 100.

[0058] In S902, the task management unit 504 of the monitoring device 101 requests the authorization server 112 for tenant information (hereinafter referred to as tenant information) to which the monitoring device 101 belongs. This request may include credentials, the agent ID obtained in S901, and the customer ID obtained in S901. Default credentials pre-stored in the data management unit 503 of the monitoring device 101 may be used as credentials.

[0059] In S903, the authorization server 112 transmits tenant information to the monitoring device 101 upon receiving a request for tenant information. The tenant information may include the tenant ID and tenant name of the tenant to which the monitoring device 101 belongs. The authorization server 112 may store the tenant ID and tenant name for each tenant in advance, or it may query the device management server 111 for the tenant ID and tenant name.

[0060] In S904, the screen control unit 505 of the monitoring device 101 presents tenant information to the user 900. The user 900 checks the presented tenant information and decides whether to continue the registration process. If the tenant information could not be obtained in S903, the screen control unit 505 presents an error to the user 900. In this case, the monitoring device 101 may terminate the process shown in Figure 9.

[0061] In S905, the screen control unit 505 of the monitoring device 101 receives an instruction from the user 900 to continue the registration process. Alternatively, the screen control unit 505 terminates the process if it receives an instruction from the user 900 to cancel the registration process.

[0062] In S906, the task management unit 504 of the monitoring device 101 executes the self-registration process of the monitoring device 101 in response to receiving an instruction from user 900 to continue the registration process. Details of this process will be described later. Through the self-registration process, the task management unit 504 obtains a token from the authorization server 112. This token is used by the monitoring device 101 to use services provided by servers other than the authorization server 112 of the management system 100.

[0063] In S907, the screen control unit 505 of the monitoring device 101 notifies the user 900 that the registration of the monitoring device 101 is complete, in response to the completion of the self-registration process of the monitoring device 101. If an error occurs during the self-registration process of the monitoring device 101 and the registration of the monitoring device 101 cannot be completed, the screen control unit 505 may notify the user 900 of the error. In this case, the monitoring device 101 may terminate the process shown in Figure 9.

[0064] In S908, the task management unit 504 of the monitoring device 101 uses the token obtained in S906 to request a list of managed image forming machines 102 (hereinafter referred to as the device list) from the device management server 111. This request may also include the agent ID obtained in S901.

[0065] In S909, the device management server 111 identifies the image forming apparatus 102 associated with the received agent ID by referring to the device management table 610. Subsequently, the device management server 111 sends a device list containing the information of the identified image forming apparatus 102 to the monitoring device 101. The monitoring device 101 thus obtains the device list from the device management server 111. The information of each image forming apparatus 102 included in the device list may include the server-assigned device ID 611, serial number 612, and tenant ID 613 of each image forming apparatus 102. Furthermore, the information of each image forming apparatus 102 included in the device list may also include the IP address, hostname, MAC address, etc. of each image forming apparatus 102.

[0066] The data management unit 503 of the monitoring device 101 generates or updates records in the device management table 700 for each image forming apparatus 102 included in the device list. Specifically, the data management unit 503 updates the information in the existing record if a record with a server-assigned device ID 707 that matches a server-assigned device ID included in the device list is included in the device management table 700. If no such record is included in the device management table 700, the data management unit 503 generates a new record.

[0067] The data management unit 503 may set the device ID 701, serial number 702, IP address 703, and server-assigned device ID 707 for new records using information included in the device list. The data management unit 503 may set the management status 704 to "target" for both existing and new records. The data management unit 503 may change the management status 704 in response to instructions from the user 900, the service provider server 114, etc. The data management unit 503 may set the registration status 705 to "unregistered" for new records. The data management unit 503 may change the registration status 705 to "registered" in response to the image forming apparatus 102 being registered with the authorization server 112. The data management unit 503 sets the monitoring method 706 to proxy method ("proxy") or polling method ("polling") for new records. This setting may be done based on pre-configured rules. The data management unit 503 may change the monitoring method 706 in accordance with instructions from the user 900, instructions from the service provision server 114, etc.

[0068] In S910, the screen control unit 505 of the monitoring device 101 notifies the user 900 that the acquisition of the device list is complete. If an error occurs during the acquisition of the device list and the acquisition of the device list cannot be completed, the screen control unit 505 may notify the user 900 of the error. In this case, the monitoring device 101 may terminate the process shown in Figure 9.

[0069] In S911, the task management unit 504 of the monitoring device 101, having obtained the device list from the device management server 111, executes the registration process for each image forming apparatus 102 included in the device list. Details of this process will be described later. Subsequently, the monitoring device 101 begins monitoring the image forming apparatus 102 to be managed.

[0070] [Connection settings screen] Referring to Figure 10, an example of a screen 1000 displayed by the screen control unit 505 of the monitoring device 101 to obtain an instruction from user 900 to start the registration process at S901 in Figure 9 will be described. The monitoring device 101 obtains connection settings from user 900 through screen 1000. Screen 1000 may be displayed on a display device connected to the output I / F 304 of the computer 300 operating as the monitoring device 101. The screen control unit 505 displays screen 1000 in response to instructions from user 900.

[0071] Screen 1000 includes a proxy settings section 1001, a connection service settings section 1008, a register button 1011, and a cancel button 1012. The proxy settings section 1001 is for obtaining the settings of a proxy server located in the communication path between the monitoring device 101 and the wide area network 120. Such a proxy server is referred to as the parent proxy.

[0072] The proxy settings section 1001 includes a checkbox 1002 and text boxes 1003 and 1004. The monitoring device 101 uses checkbox 1002 to obtain instructions from user 900 to connect to the wide area network 120 via the parent proxy. The monitoring device 101 uses text box 1003 to obtain the IP address of the parent proxy from user 900. The monitoring device 101 uses text box 1004 to obtain the port number of the parent proxy from user 900. The monitoring device 101 may enable input to text boxes 1003 and 1004 when checkbox 1002 is checked. The monitoring device 101 may disable input to text boxes 1003 and 1004 when checkbox 1002 is unchecked.

[0073] The proxy settings section 1001 further includes a checkbox 1005 and text boxes 1006 and 1007. The monitoring device 101 uses checkbox 1005 to obtain instructions from user 900 to use credentials (e.g., a password) to connect to the parent proxy. The monitoring device 101 uses text box 1006 to obtain the username to be used for login from user 900. The monitoring device 101 uses text box 1007 to obtain the password to be used for login from user 900. The monitoring device 101 may enable input to text boxes 1006 and 1007 when checkbox 1005 is checked. The monitoring device 101 may disable input to text boxes 1006 and 1007 when checkbox 1005 is unchecked.

[0074] The connection service configuration section 1008 is a section for obtaining information used by the monitoring device 101 to request registration of the monitoring device 101 from the authorization server 112. The connection service configuration section 1008 includes text boxes 1009 and 1010. The monitoring device 101 uses text box 1009 to obtain the agent ID from user 900. The monitoring device 101 uses text box 1010 to obtain the customer ID from user 900. The obtained agent ID and customer ID are sent to the authorization server 112 as described in Figure 9.

[0075] In response to the registration button 1011 being pressed by user 900, monitoring device 101 obtains the information specified in proxy settings section 1001 and connection service settings section 1008 as instructions for S901. In response to the cancel button 1012 being pressed by user 900, monitoring device 101 returns to the previous screen without performing connection settings.

[0076] [Connection settings screen] Referring to Figure 11, an example of screen 1100 containing tenant information presented to user 900 in S904 of Figure 9 is described. Screen 1100 may be displayed on a display device connected to the output I / F 304 of computer 300 operating as monitoring device 101.

[0077] Screen 1100 includes a warning icon, a document requesting tenant confirmation, a tenant ID field 1101, a tenant name field 1102, an OK button 1103, and a cancel button 1104. The tenant ID field 1101 displays the tenant ID included in the tenant information obtained in S903. The tenant name field 1102 displays the tenant name included in the tenant information obtained in S903.

[0078] The monitoring device 101 determines that user 900 has confirmed the tenant information when the OK button 1103 is pressed by user 900. The monitoring device 101 determines that user 900 does not wish to continue processing when the Cancel button 1104 is pressed by user 900. In this case, the monitoring device 101 may display screen 1000 again.

[0079] [Self-registration process for monitoring devices] Referring to Figure 12, the self-registration process of the monitoring device 101 performed in S906 of Figure 9 will be described in detail. In S1201, the task management unit 504 of the monitoring device 101 requests an activation code from the authorization server 112. This request may include credentials, the agent ID obtained in S901, and the customer ID obtained in S901. The credentials may be default credentials that are pre-stored in the data management unit 503 of the monitoring device 101.

[0080] In S1202, the authorization server 112 refers to the agent activation code management table 800 and identifies a record having agent ID 802 and customer ID 803 that match the agent ID and customer ID received from the monitoring device 101. If the authorization server 112 can identify such a record, it verifies the validity of the activation code 801 based on the expiration date 804 of this record. Furthermore, the authorization server 112 may also verify the credentials received from the monitoring device 101. If the activation code 801 is valid, the authorization server 112 sends the activation code 801 to the monitoring device 101. If the authorization server 112 cannot identify such a record, or if the activation code 801 is not valid, it may send an error to the monitoring device 101.

[0081] In S1203, the task management unit 504 of the monitoring device 101 requests the authorization server 112 to activate the monitoring device 101 in response to receiving the activation code. This request may include the activation code obtained in S1202 and the agent ID obtained in S901.

[0082] In S1204, the authorization server 112 refers to the agent activation code management table 800 and identifies a record with activation code 801 and agent ID 802 that matches the activation code and agent ID received from the monitoring device 101. If the authorization server 112 can identify such a record, it verifies the validity of activation code 801 based on the expiration date 804 of this record. If activation code 801 is valid, the authorization server 112 issues credentials. The authorization server 112 also adds a new record to the credential management table 840. The authorization server 112 sets the agent ID received from the monitoring device 101 to client ID 841 and sets the issued credentials to credential 842.

[0083] In S1205, the authorization server 112 sends the issued credentials to the monitoring device 101. The authorization server 112 may send an error to the monitoring device 101 if it cannot identify the record in S1204 or if the activation code 801 is invalid.

[0084] The authorization server 112 may consider a client with credentials 842, managed in the credential management table 840, as a client registered with it. Therefore, the request sent by the monitoring device 101 in S1203 (a request to activate) may be considered a request to register the monitoring device 101 with the authorization server 112.

[0085] In S1206, the task management unit 504 of the monitoring device 101 requests a token from the authorization server 112. This request may include the credentials obtained in S1205 and the agent ID obtained in S901.

[0086] In S1207, the authorization server 112 refers to the credential management table 840 to verify the validity of the credentials received from the monitoring device 101. If the credentials are valid, the authorization server 112 issues a token.

[0087] In S1208, the authorization server 112 sends the issued token to the monitoring device 101. The authorization server 112 may also send an error to the monitoring device 101 if the credentials are not valid in S1207.

[0088] In S1209, the task management unit 504 of the monitoring device 101 requests the URL of the resource server 113 and the URL of the device management server 111 from the access destination management server 115. This request may be accompanied by the token obtained in S1208. The URL of the access destination management server 115 may be stored in advance by the data management unit 503. In S1210, the access destination management server 115 sends the URL of the resource server 113 and the URL of the device management server 111 to the monitoring device 101.

[0089] In S1211, the task management unit 504 of the monitoring device 101 performs a communication test with the resource server 113. In S1212, the task management unit 504 of the monitoring device 101 performs a communication test with the device management server 111. In S1213, the task management unit 504 of the monitoring device 101 sends the results of the communication test to the resource server 113.

[0090] [Registration process for image forming apparatus] Referring to Figure 13, the registration process of the image forming apparatus 102 performed in S911 of Figure 9 will be described in detail. In S1301, the device management unit 501 of the monitoring device 101 requests device information from the image forming apparatus 102 by using the IP address 703 and hostname included in the device management table 700. The device information may include the MAC address and serial number of the image forming apparatus 102. In S1302, the image forming apparatus 102 responds to this request and transmits the device information to the monitoring device 101.

[0091] In S1303, the device management unit 501 of the monitoring device 101 determines whether the serial number 702 in the device management table 700 matches the serial number obtained in S1302. If these serial numbers do not match, the device management unit 501 may terminate the process on the grounds that the IP address of the image forming apparatus 102 has been changed. In addition to or instead of this, the device management unit 501 may terminate the process if the serial number obtained in S909 does not match the serial number obtained in S1302. In addition to or instead of this, if the serial numbers cannot be compared, the device management unit 501 may terminate the process if the MAC address obtained in S909 does not match the MAC address obtained in S1302.

[0092] In S1304, the device management unit 501 of the monitoring device 101 requests the image forming apparatus 102 to provide a list of services it offers. In S1305, the image forming apparatus 102 responds to this request by sending a list of services it offers to the monitoring device 101.

[0093] The monitoring device 101 determines whether the image forming apparatus 102 has a self-registration function with the authorization server 112 based on the list of services acquired in S1305. The self-registration function is a function that performs a self-registration process with the authorization server 112. The self-registration function includes a function that sends a request to the authorization server 112 asking to register itself with the authorization server 112. The monitoring device 101 determines that the image forming apparatus 102 has a self-registration function with the authorization server 112 if the list of services acquired in S1305 includes the self-registration function.

[0094] In S1306, the device management unit 501 of the monitoring device 101 determines the method of registration processing for registering the image forming apparatus 102 with the authorization server 112. The device management unit 501 selects either a registration process that uses the self-registration function or a registration process that does not use the self-registration function. As described above, the registration process that uses the self-registration function is called the self-registration process. In the registration process that does not use the self-registration function, as will be described later, the monitoring device 101 performs the registration process on behalf of the image forming apparatus 102. For this reason, such a process is referred to as the substitute registration process. If the self-registration process is selected, the monitoring device 101 may execute S1307 to S1308. If the substitute registration process is selected, the monitoring device 101 may execute S1309 to S1310.

[0095] First, the device management unit 501 refers to the monitoring method 706 in the device management table 700 to determine the monitoring method for monitoring the image forming apparatus 102 included in the device list. For image forming apparatus 102 that are configured with a method other than the proxy method (for example, the polling method), the device management unit 501 selects an alternative registration process. For image forming apparatus 102 that are configured with the proxy method, the device management unit 501 determines whether the image forming apparatus 102 has a self-registration function.

[0096] For an image forming apparatus 102 that is configured with a proxy method and has a self-registration function, the device management unit 501 selects the self-registration process. For an image forming apparatus 102 that is configured with a proxy method and does not have a self-registration function, the device management unit 501 cannot select the self-registration process. In such cases, the device management unit 501 changes the monitoring method of the image forming apparatus 102 to a polling method and selects the alternative registration process. In this way, the device management unit 501 may determine the monitoring method of the image forming apparatus 102 based on whether the image forming apparatus 102 has a function (for example, a self-registration process) required for the monitoring device 101 to monitor the image forming apparatus 102 using a proxy method.

[0097] In S1307, the monitoring device 101 uses credentials to check whether it can access the authorization processing unit 401 of the image forming apparatus 102. In this check, the monitoring device 101 uses credentials that external devices on the network via the LAN 121 use to access the authorization processing unit 401 of the image forming apparatus 102. Such credentials may be stored in the monitoring device 101 in advance, or they may be set by the user 900 using the screen control unit 505. If the monitoring device 101 cannot access the authorization processing unit 401 of the image forming apparatus 102, it may terminate the process.

[0098] In S1308, the monitoring device 101 registers the image forming apparatus 102 with the authorization server 112 using the image forming apparatus 102's self-registration function. Details of this process will be described later.

[0099] In S1309, the device management unit 501 of the monitoring device 101 checks whether it can obtain information used for monitoring (for example, product name, product type, number of printed pages, consumable information, error status, error log, etc.) from the image forming apparatus 102. The monitoring device 101 may terminate processing if it cannot obtain such information.

[0100] In S1310, the monitoring device 101 registers the image forming apparatus 102 with the authorization server 112, replacing the image forming apparatus 102. Details of this process will be described later.

[0101] [Monitoring method setting screen] Referring to Figure 14, an example of a screen 1400 displayed by the screen control unit 505 of the monitoring device 101 to obtain the monitoring method setting for the image forming apparatus 102 from the user 900 will be described. The screen 1400 includes a radio button 1401, text boxes 1402 and 1403, a save button 1404, and a cancel button 1405. The monitoring method may be set collectively for all image forming apparatuses 102 managed by the monitoring device 101. Alternatively, the monitoring method may be set individually for each image forming apparatus 102 managed by the monitoring device 101.

[0102] The monitoring device 101 obtains the monitoring method setting for the image forming apparatus 102 from the user 900 using radio buttons 1401. Two monitoring methods are available: proxy method and polling. Alternatively, the monitoring device 101 may monitor the image forming apparatus 102 using other monitoring methods.

[0103] The monitoring device 101 obtains the IP address of the proxy server from user 900 using text box 1402. The monitoring device 101 obtains the port number of the proxy server from user 900 using text box 1403. The monitoring device 101 may enable input to text boxes 1402 and 1403 if the proxy method is selected with radio button 1401. The monitoring device 101 may disable input to text boxes 1402 and 1403 if the polling method is selected with radio button 1401.

[0104] When the user 900 presses the save button 1404, the monitoring device 101 stores the settings configured on screen 1400 in the data management unit 503. When the user 900 presses the cancel button 1405, the monitoring device 101 returns to the previous screen without configuring the monitoring method.

[0105] The monitoring device 101 determines the validity of the input contents in text boxes 1402 and 1403 in response to the save button 1404 being pressed with the proxy method selected by radio button 1401. If the input in text box 1402 is not a valid IP address, or if the port number entered in text box 1403 is already in use, the monitoring device 101 may notify the user 900 that the settings cannot be applied.

[0106] The monitoring device 101 enables the proxy unit 502 when it determines that the input contents in text boxes 1402 and 1403 are valid. This causes the monitoring device 101 to operate as a proxy server according to the input contents (IP address and port number) in text boxes 1402 and 1403.

[0107] An image forming apparatus 102 monitored in proxy format communicates with a server in the management system 100 through a designated proxy server (e.g., monitoring device 101) and utilizes services provided by this server. The monitoring device 101 monitors the communication data exchanged between the image forming apparatus 102 and the server. The proxy format can be configured for image forming apparatus 102 that has a function to utilize services (e.g., a self-registration function). The monitoring device 101 monitors image forming apparatus 102 that has a function to utilize services (e.g., a self-registration function) using a monitoring method other than the proxy format (e.g., a polling method).

[0108] In the proxy system, the server within the management system 100 only needs to update the configuration of the image forming apparatus 102 (e.g., the application) to provide new services, and there is no need to change the configuration of the monitoring device 101. Furthermore, since the monitoring device 101 does not need to actively acquire information from the image forming apparatus 102 and provide it to the server, the processing load on the monitoring device 101 is reduced. Because the server within the management system 100 can issue instructions directly to the image forming apparatus 102, it can respond to requests from the image forming apparatus 102 with real-time remote commands. For example, the server can send remote commands that have a high probability of success without having to manage the sleep or power-off of the image forming apparatus 102.

[0109] On the other hand, in the proxy method, when communication between the image forming apparatus 102 and the server is encrypted, the monitoring device 101, which functions as a proxy server, requires individual settings such as intermediate certificates to understand the content of that communication. Therefore, although the monitoring device 101 can display the time of communication between the image forming apparatus 102 and the server as a communication log, it may be difficult to display the content of that communication.

[0110] The image forming apparatus 102, which is monitored by a polling method, does not communicate with the server in the management system 100. Instead, the image forming apparatus 102 sends information used by the server in the management system 100 to the monitoring device 101 in response to polling from the monitoring device 101. The monitoring device 101 sends the information obtained from the image forming apparatus 102 to the server in the management system 100. The image forming apparatus 102, which is monitored by a polling method, does not perform self-registration processing. Therefore, the monitoring device 101 can monitor the image forming apparatus 102 by polling method regardless of whether the image forming apparatus 102 has the capability to perform self-registration processing.

[0111] In the polling method, the monitoring device 101 can understand the content of the information acquired from the image forming apparatus 102, making it easier to manage and control the monitoring device 101. For example, the monitoring device 101 can display communication logs to the user 900 or set the time period for collecting information from the image forming apparatus 102. In addition, with the polling method, the monitoring device 101 can collect information from older devices that do not have the capability to perform self-registration processing, or from devices that do not have the capability to support the server in the management system 100.

[0112] On the other hand, with the polling method, the monitoring device 101 needs to be updated in order for the server in the management system 100 to provide new services. Also, due to the processing burden on the monitoring device 101 to collect information from the image forming apparatus 102, the number of image forming apparatuses 102 that can be managed may be less than with the proxy method.

[0113] [Self-registration process for image forming apparatus] Referring to Figure 15, the details of the process of registering the image forming apparatus 102 with the authorization server 112 using the self-registration function, which is executed in S1308 of Figure 13, will be explained. In S1501, the device management unit 501 of the monitoring device 101 queries the authorization processing unit 401 of the image forming apparatus 102 about the registration status with the authorization server 112. In S1502, the authorization processing unit 401 of the image forming apparatus 102 responds to this query and notifies the monitoring device 101 of its own registration status, that is, whether or not it is registered with the authorization server 112. The authorization processing unit 401 of the image forming apparatus 102 stores the registration status with the authorization server 112 in, for example, RAM 203. If the image forming apparatus 102 is already registered with the authorization server 112, the monitoring device 101 terminates processing. If the image forming apparatus 102 is not registered with the authorization server 112, the monitoring device 101 executes the processing from S1503 onwards.

[0114] In S1503, the device management unit 501 of the monitoring device 101 requests a device registration key from the device management server 111. This request may include the server-assigned device ID of the image forming apparatus 102 to be registered and the token obtained in S1208. The device management unit 501 may use the server-assigned device ID 707 from the device management table 700 as this server-assigned device ID.

[0115] In S1504, the device management server 111 verifies the token received from the monitoring device 101. After successfully verifying the token, the device management server 111 determines whether a record with a server-assigned device ID 611 matching the server-assigned device ID received from the monitoring device 101 is included in the device management table 610. The inclusion of such a record in the device management table 610 means that the image forming apparatus 102 to be registered is managed by the device management server 111. If the image forming apparatus 102 to be registered is managed by the device management server 111, the device management server 111 requests a device registration key from the device management server 111. This request may be accompanied by the server-assigned device ID obtained in S1503.

[0116] In S1505, the authorization server 112 determines whether a record with a client ID 831 matching the server-assigned device ID received in S1504 is included in the client management table 830. The inclusion of such a record in the client management table 830 means that the image forming apparatus 102 to be registered is managed by the authorization server 112. If the image forming apparatus 102 to be registered is managed by the authorization server 112, the authorization server 112 issues a device registration key. The authorization server 112 adds a new record to the registration key management table 820. The authorization server 112 sets the issued device registration key as the device registration key 821 of the new record. The authorization server 112 sets the tenant ID 833 of the client management table 830 as the tenant ID 822 of the new record. The authorization server 112 sets the expiration date 823 of the new record according to the pre-configured rules.

[0117] In S1506, the authorization server 112 sends the device registration key issued in S1505 to the device management server 111. In S1507, the device management server 111 sends the device management key received in S1506 to the monitoring device 101.

[0118] In S1508, the device management unit 501 of the monitoring device 101 instructs the image forming apparatus 102 to use a designated proxy server. This instruction may include information about the proxy server. The proxy server information may include an IP address and a port number. The proxy server information may also be an IP address and port number obtained from the user 900 through the screen 1400 in Figure 14. The monitoring device 101 may operate as a proxy server having this IP address and port number. Alternatively, the monitoring device 101 may transmit information about a proxy server other than the monitoring device 101 to the image forming apparatus 102. In this case, the monitoring device 101 may obtain communication data from the image forming apparatus 102 from this proxy server.

[0119] In S1509, the data management unit 402 of the image forming apparatus 102 sets the proxy server information received in S1508. Subsequently, the image forming apparatus 102 starts using the set proxy server. Therefore, communication between the image forming apparatus 102 and the wide area network 120 goes through the set proxy server. In S1510, the data management unit 402 of the image forming apparatus 102 notifies the monitoring device 101 that the proxy server setup is complete.

[0120] In S1511, the device management unit 501 of the monitoring device 101 queries the authorization processing unit 401 of the image forming apparatus 102 for information on the proxy server configured in the image forming apparatus 102. In S1512, the authorization processing unit 401 of the image forming apparatus 102 transmits the configured proxy server information to the monitoring device 101. The data management unit 503 of the monitoring device 101 stores the received proxy server information.

[0121] In S1513, the device management unit 501 of the monitoring device 101 instructs the image forming apparatus 102 to send a request to the authorization server 112 to register the image forming apparatus 102 with the authorization server 112. This instruction may be accompanied by the device registration key obtained in S1507. In S1514, the image forming apparatus 102 sends an acknowledgment to the monitoring device 101.

[0122] In S1515, the authorization processing unit 401 of the image forming apparatus 102 requests an activation code from the authorization server 112. This request may include the device registration key obtained in S1513 and the serial number of the image forming apparatus 102. The serial number of the image forming apparatus 102 is stored, for example, in the ROM 202.

[0123] In S1516, the authorization server 112 refers to the registration key management table 820 and identifies a record having a device registration key 821 that matches the device registration key obtained in S1515. The authorization server 112 verifies the validity of the device registration key based on the expiration date 823 of this record. If the device registration key is valid, the authorization server 112 issues an activation code. The authorization server 112 adds a new record to the device activation code management table 810. The authorization server 112 sets the issued activation code as the activation code 811 of the new record. The authorization server 112 sets the serial number obtained in S1515 as the serial number 812 of the new record. The authorization server 112 sets the device registration key obtained in S1515 as the device registration key 813 of the new record. The authorization server 112 sets the expiration date 814 of the new record according to a pre-configured rule.

[0124] In S1517, the authorization server 112 sends an activation code to the image forming apparatus 102. The authorization server 112 may send an error to the image forming apparatus 102 if it cannot identify such a record or if the device registration key is invalid.

[0125] In S1518, the authorization processing unit 401 of the image forming apparatus 102 requests the authorization server 112 to activate the image forming apparatus 102 in response to receiving the activation code. This request may include the activation code obtained in S1517, the device registration key obtained in S1513, and the serial number of the image forming apparatus 102. The serial number of the image forming apparatus 102 is stored, for example, in the ROM 202.

[0126] In S1519, the authorization server 112 refers to the device activation code management table 810 and identifies a record with activation code 811, serial number 812, and device registration key 813 that matches the activation code, serial number, and device registration key obtained in S1518. If the authorization server 112 can identify such a record, it verifies the validity of activation code 811 based on the expiration date 814 of this record. If activation code 811 is valid, the authorization server 112 issues credentials. The authorization server 112 also adds a new record to the credential management table 840. The authorization server 112 sets the serial number obtained in S1518 to client ID 841 and sets the issued credentials to credentials 842.

[0127] In S1520, the authorization server 112 sends the issued credentials to the image forming apparatus 102. The authorization server 112 may send an error to the image forming apparatus 102 if it cannot identify the record in S1519 or if the activation code 811 is invalid.

[0128] The authorization server 112 may consider a client having credentials 842, which are managed in the credential management table 840, as a client registered with it. Therefore, the request sent by the image forming apparatus 102 in S1518 (a request to activate) may be considered a request to register the image forming apparatus 102 with the authorization server 112.

[0129] In response to receiving an acknowledgment in S1514, the monitoring device 101 may confirm the registration status of the image forming apparatus 102 in S1521. Details of this process will be described later. In an embodiment in which the acknowledgment in S1514 is omitted, the monitoring device 101 may execute the process in S1521 in response to sending an instruction in S1513.

[0130] [Confirmation of registration status] Referring to Figure 16, the details of the registration status verification process performed in S1521 of Figure 15 will be explained. In S1601, the device management unit 501 of the monitoring device 101 initializes a counter to 0. This counter counts the number of attempts to perform the registration status verification process.

[0131] In S1602, the device management unit 501 of the monitoring device 101 obtains the registration status of the image forming apparatus 102 with the authorization server 112. For example, the device management unit 501 queries the authorization processing unit 401 of the image forming apparatus 102 for the registration status. In response to this query, the device management unit 501 obtains the registration status of the image forming apparatus 102 with the authorization server 112.

[0132] In S1603, the device management unit 501 of the monitoring device 101 determines whether the registration status of the image forming apparatus 102 is registered. If the device management unit 501 determines that it is registered (YES in S1603), it proceeds to S1607; otherwise, if it determines that it is not registered (NO in S1603), it proceeds to S1604. In S1607, the device management unit 501 of the monitoring device 101 sets the registration status 705 of the target record in the device management table 700 to "registered". If the registration status 705 was already "registered", the device management unit 501 maintains the registration status 705 as "registered".

[0133] In S1604, the device management unit 501 of the monitoring device 101 increments the counter by 1. In S1605, the device management unit 501 determines whether the counter has reached a predetermined number of times. If the device management unit 501 determines that the counter has reached a predetermined number of times (YES in S1605), it transitions the process to S1606; otherwise (NO in S1605), it transitions the process to S1602. The predetermined number of times the counter has been reached may be set in advance and stored in the monitoring device 101. In this way, the device management unit 501 repeatedly obtains the registration status managed by the image forming apparatus 102 from the image forming apparatus 102.

[0134] In S1606, the device management unit 501 of the monitoring device 101 sets the registration status 705 of the target record in the device management table 700 to "Not registered".

[0135] [Alternative registration process for image forming apparatus] Referring to Figure 17, the details of the process performed in S1310 of Figure 13 to register the image forming apparatus 102 with the authorization server 112 as a replacement for the image forming apparatus 102 will be explained. In S1701, the device management unit 501 of the monitoring device 101 requests a device registration key from the device management server 111. This request may include the server-assigned device ID of the image forming apparatus 102 to be registered and the token obtained in S1208. The device management unit 501 may use the server-assigned device ID 707 from the device management table 700 as this server-assigned device ID.

[0136] In S1702, the device management server 111 verifies the token received from the monitoring device 101. After successfully verifying the token, the device management server 111 determines whether a record with a server-assigned device ID 611 matching the server-assigned device ID received from the monitoring device 101 is included in the device management table 610. The inclusion of such a record in the device management table 610 means that the image forming apparatus 102 to be registered is managed by the device management server 111. If the image forming apparatus 102 to be registered is managed by the device management server 111, the device management server 111 requests a device registration key from the device management server 111. This request may be accompanied by the server-assigned device ID obtained in S1701.

[0137] In S1703, the authorization server 112 determines whether a record with a client ID 831 matching the server-assigned device ID received in S1702 is included in the client management table 830. The inclusion of such a record in the client management table 830 means that the image forming apparatus 102 to be registered is managed by the authorization server 112. If the image forming apparatus 102 to be registered is managed by the authorization server 112, the authorization server 112 issues a device registration key. The authorization server 112 adds a new record to the registration key management table 820. The authorization server 112 sets the issued device registration key as the device registration key 821 of the new record. The authorization server 112 sets the tenant ID 833 of the client management table 830 as the tenant ID 822 of the new record. The authorization server 112 sets the expiration date 823 of the new record according to the pre-configured rules.

[0138] In S1704, the authorization server 112 sends the device registration key issued in S1703 to the device management server 111. In S1705, the device management server 111 sends the device management key received in S1704 to the monitoring device 101.

[0139] In S1706, the device management unit 501 of the monitoring device 101 requests an activation code from the authorization server 112. This request may include the device registration key obtained in S1705 and the serial number of the image forming apparatus 102. The serial number of the image forming apparatus 102 is stored, for example, in serial number 702 of the device management table 700.

[0140] In S1707, the authorization server 112 refers to the registration key management table 820 and identifies a record having a device registration key 821 that matches the device registration key obtained in S1706. The authorization server 112 verifies the validity of the device registration key based on the expiration date 823 of this record. If the device registration key is valid, the authorization server 112 issues an activation code. The authorization server 112 adds a new record to the device activation code management table 810. The authorization server 112 sets the issued activation code as the activation code 811 of the new record. The authorization server 112 sets the serial number obtained in S1706 as the serial number 812 of the new record. The authorization server 112 sets the device registration key obtained in S1706 as the device registration key 813 of the new record. The authorization server 112 sets the expiration date 814 of the new record according to a pre-configured rule.

[0141] In S1708, the authorization server 112 sends an activation code to the monitoring device 101. The authorization server 112 may send an error to the monitoring device 101 if it cannot identify such a record or if the device registration key is invalid.

[0142] In S1709, the device management unit 501 of the monitoring device 101 requests the authorization server 112 to activate the image forming apparatus 102 in response to receiving the activation code. This request may include the activation code obtained in S1708, the device registration key obtained in S1705, and the serial number of the image forming apparatus 102. The serial number of the image forming apparatus 102 is stored, for example, in serial number 702 of the device management table 700.

[0143] In S1710, the authorization server 112 refers to the device activation code management table 810 and identifies a record with activation code 811, serial number 812, and device registration key 813 that matches the activation code, serial number, and device registration key obtained in S1709. If the authorization server 112 can identify such a record, it verifies the validity of activation code 811 based on the expiration date 814 of this record. If activation code 811 is valid, the authorization server 112 issues credentials. The authorization server 112 also adds a new record to the credential management table 840. The authorization server 112 sets the serial number obtained in S1709 to client ID 841 and the issued credentials to credential 842.

[0144] In S1711, the authorization server 112 sends the issued credentials to the monitoring device 101. The authorization server 112 may send an error to the monitoring device 101 if it cannot identify the record in S1710 or if the activation code 811 is invalid.

[0145] The authorization server 112 may consider a client having credentials 842, which are managed in the credential management table 840, as a client registered with it. Therefore, the request sent by the monitoring device 101 in S1709 (a request to activate) may be considered a request to register the image forming apparatus 102 with the authorization server 112.

[0146] According to the first embodiment, a device with a self-registration function (e.g., an image forming apparatus 102) is instructed to set up a proxy server before executing the self-registration process, allowing the monitoring device 101 to monitor the device's communication with an external server. Furthermore, for devices without a self-registration function (e.g., an image forming apparatus 102), the monitoring device 101 performs the registration process on their behalf and obtains information by polling. Therefore, devices without a self-registration function do not communicate freely with external servers. As described above, the monitoring device 101 centrally aggregates and performs the registration process for devices.

[0147] <Second Embodiment> Referring to Figure 18, the management system 100 according to the second embodiment will be described. In the second embodiment, the process of registering the image forming apparatus 102 with the authorization server 112 using the self-registration function, which is performed in S1308 of Figure 13, differs from the process in the first embodiment. Matters that are omitted from the explanation in the second embodiment may be the same as those in the first embodiment.

[0148] In the first embodiment, as described in detail with reference to Figure 15, the monitoring device 101 terminates processing if the registration status of the image forming apparatus 102 acquired in S1502 is registered. However, even if the image forming apparatus 102 is registered, it is possible that the image forming apparatus 102 has already been registered with the authorization server 112 by its self-registration function before the monitoring device 101 executes the registration process. It is also possible that it has been registered with the authorization server 112 by a monitoring device other than the monitoring device 101. In such cases, the monitoring device 101 cannot monitor this registered image forming apparatus 102. Therefore, in the second embodiment, the monitoring device 101 deregisters such image forming apparatus 102 and then registers it with the authorization server 112 again.

[0149] [Self-registration process for image forming apparatus] Referring to Figure 18, the details of the process of registering the image forming apparatus 102 with the authorization server 112 using the self-registration function, which is performed in S1308 of Figure 13 in the second embodiment, will be explained. First, the monitoring device 101 performs the same processes as S1501 and S1502 in Figure 15. If the registration status of the image forming apparatus 102 obtained in S1502 is registered, the monitoring device 101 performs S1801 to S1805. After that, the monitoring device 101 performs the same processes as S1503 onwards in Figure 15.

[0150] In S1801, the device management unit 501 of the monitoring device 101 instructs the image forming apparatus 102 to use a designated proxy server. This instruction may include information about the proxy server. The proxy server information may include an IP address and a port number. The proxy server information may also be an IP address and port number obtained from the user 900 through the screen 1400 in Figure 14. The monitoring device 101 may operate as a proxy server having this IP address and port number. Alternatively, the monitoring device 101 may transmit information about a proxy server other than the monitoring device 101 to the image forming apparatus 102. In this case, the monitoring device 101 may obtain communication data from the image forming apparatus 102 from this proxy server.

[0151] In S1802, the data management unit 402 of the image forming apparatus 102 sets the proxy server information received in S1801. Subsequently, the image forming apparatus 102 starts using the set proxy server. Therefore, communication between the image forming apparatus 102 and the wide area network 120 goes through the set proxy server. In S1803, the data management unit 402 of the image forming apparatus 102 notifies the monitoring device 101 that the proxy server setup is complete.

[0152] In S1804, the device management unit 501 of the monitoring device 101 instructs the image forming apparatus 102 to send a request to the authorization server 112 to deregister the image forming apparatus 102. The authorization processing unit 401 of the image forming apparatus 102 sends a request to the authorization server 112 to deregister the image forming apparatus 102 in response to this instruction. The authorization server 112 deletes the information of the image forming apparatus 102 from each table in response to this request. As a result, the authorization server 112 deregisters the image forming apparatus 102. In S1805, the authorization processing unit 401 of the image forming apparatus 102 notifies the monitoring device 101 that the deregistration was successful.

[0153] Instead of instructing the image forming apparatus 102 to deregister, the monitoring device 101 may perform the registration process for the image forming apparatus 102 even if the image forming apparatus 102 is already registered. When the authorization server 112 receives a new registration request for an already registered image forming apparatus 102, it may update the registration details of the image forming apparatus 102 according to the new registration request.

[0154] According to the second embodiment, even if the image forming apparatus 102 has already been registered with the authorization server 112, the monitoring device 101 can aggregate and monitor it.

[0155] <Summary of Embodiments> [Item 1] A monitoring device that monitors devices, A means of obtaining a device list from a device management server, A determination means for determining a monitoring method for monitoring the devices included in the device list, The system includes registration processing means that executes a first registration process to register a first device monitored by a first monitoring method with an authorization server, and executes a second registration process different from the first registration process to register a second device monitored by a second monitoring method different from the first monitoring method with the authorization server, The first registration process described above is: Instructing the first device to use the specified proxy server, A monitoring device that includes instructing the first device to send a request to the authorization server asking the first device to register with the authorization server after the first device has started using the designated proxy server. [Item 2] The monitoring device according to item 1, wherein the second registration process includes sending a request to the authorization server requesting that the second device be registered with the authorization server. [Item 3] The monitoring device according to item 1 or 2, wherein the determination means determines the monitoring method for the device based on whether the device has functions required for the monitoring device to monitor the device in the first monitoring method. [Item 4] The monitoring device according to item 3, wherein the required function includes a function that sends a request to the authorization server requesting that the device be registered with the authorization server. [Item 5] The registration processing means further performs a third registration process, which includes sending a request to the authorization server to register the monitoring device with the authorization server. The acquisition means is a monitoring device according to any one of items 1 to 4, which acquires the device list from the device management server after the third registration process has been executed. [Item 6] The monitoring device according to any one of items 1 to 5, wherein the first registration process further includes instructing the first device to send a request to the authorization server to deregister the first device before instructing the first device to send a request to the authorization server to register the first device with the authorization server, if the first device is already registered with the authorization server. [Item 7] The aforementioned monitoring device is In the first monitoring method, the first device monitors the communication data transmitted or received through the designated proxy server. The monitoring device according to any one of items 1 to 6, further comprising monitoring means for monitoring information acquired from the second device by polling, in the second monitoring method. [Item 8] The monitoring device according to any one of items 1 to 7, further comprising proxy means for operating the monitoring device as the designated proxy server. [Item 9] A method for controlling a monitoring device that monitors a device, The acquisition method involves the process of obtaining a device list from a device management server, The determination means includes the step of determining a monitoring method for monitoring the devices included in the device list, The registration processing means performs a first registration process to register a first device monitored by the first monitoring method with the authorization server, The registration processing means includes a step of executing a second registration process different from the first registration process in order to register a second device monitored by a second monitoring method different from the first monitoring method with the authorization server, The first registration process described above is: Instructing the first device to use the specified proxy server, A method comprising: instructing the first device to send a request to the authorization server asking the first device to register with the authorization server after the first device has started using the designated proxy server. [Item 10] A program to cause a computer to function as a monitoring device as described in any one of items 1 through 8.

[0156] The invention is not limited to the embodiments described above, and various modifications and variations are possible without departing from the spirit and scope of the invention. Accordingly, claims are attached to disclose the scope of the invention. [Explanation of Symbols]

[0157] 101 Monitoring device, 102 Image forming apparatus, 111 Device management server, 112 Authorization server

Claims

1. A monitoring device that monitors devices, A means of obtaining a device list from a device management server, A determination means for determining a monitoring method for monitoring the devices included in the device list, The system includes registration processing means that executes a first registration process to register a first device monitored by a first monitoring method with an authorization server, and executes a second registration process different from the first registration process to register a second device monitored by a second monitoring method different from the first monitoring method with the authorization server, The first registration process is as follows: Instructing the first device to use the specified proxy server, A monitoring device that includes instructing the first device to send a request to the authorization server to register the first device with the authorization server after the first device has started using the designated proxy server.

2. The monitoring device according to claim 1, wherein the second registration process includes sending a request to the authorization server requesting that the second device be registered with the authorization server.

3. The monitoring device according to claim 1, wherein the determination means determines a monitoring method for the device based on whether the device has functions required for the monitoring device to monitor the device in the first monitoring method.

4. The monitoring device according to claim 3, wherein the required function includes a function of sending a request to the authorization server to register the device with the authorization server.

5. The registration processing means further performs a third registration process, which includes sending a request to the authorization server to register the monitoring device with the authorization server. The monitoring device according to claim 1, wherein the acquisition means acquires the device list from the device management server after the third registration process is executed.

6. The monitoring device according to claim 1, wherein the first registration process further includes, if the first device is already registered with the authorization server, instructing the first device to send a request to the authorization server to deregister the first device before instructing the first device to send a request to the authorization server to register the first device with the authorization server.

7. The aforementioned monitoring device is In the first monitoring method, the first device monitors the communication data transmitted or received through the designated proxy server. The monitoring device according to claim 1, further comprising monitoring means for monitoring information acquired from the second device by polling, in the second monitoring method.

8. The monitoring device according to claim 1, further comprising proxy means for operating the monitoring device as the designated proxy server.

9. A method for controlling a monitoring device that monitors a device, The acquisition method involves the process of obtaining a device list from a device management server, The determination means includes the step of determining a monitoring method for monitoring the devices included in the device list, The registration processing means performs a first registration process to register a first device monitored by the first monitoring method with the authorization server, The registration processing means includes a step of executing a second registration process different from the first registration process in order to register a second device, which is monitored by a second monitoring method different from the first monitoring method, with the authorization server. The first registration process is as follows: Instructing the first device to use the specified proxy server, A method comprising: instructing the first device to send a request to the authorization server asking the first device to register with the authorization server after the first device has started using the designated proxy server.

10. A program for causing a computer to function as a monitoring device according to any one of claims 1 to 8.