Communication devices and computer programs for communication devices

JP7913371B2Active Publication Date: 2026-09-01BROTHER KOGYO KK
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
JP2022184110
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-11-17
Publication Date
2026-09-01
Estimated Expiration
2042-11-17

Smart Images

  • Figure 0007913371000001
    Figure 0007913371000001
  • Figure 0007913371000002
    Figure 0007913371000002
  • Figure 0007913371000003
    Figure 0007913371000003
Patent Text Reader

Abstract

To provide a technique for acquiring authentication information from an authentication server without providing any storage region for use in previously storing parameters in a communication apparatus.SOLUTION: A communication apparatus according to the present invention has a first request transmission unit for transmitting, to a specific server, a parameter request for requesting a parameter for use in communicating with an authentication server, a parameter receiving unit for receiving the parameter from the specific server, a second request transmission unit for transmitting an authentication information request for requesting authentication information to the authentication server by using the parameters received from the specific server, an authentication information receiving unit for receiving the authentication information from the authentication server as a response to the authentication information request if a specific condition that the terminal device uses specific account information to log in any of the authentication server and a service server is satisfied, and a data communication unit for communicating target data with the service server by using the authentication information received from the authentication server.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present specification relates to a communication device configured to be communicable with a server.

Background Art

[0002] Patent Document 1 discloses OAuth2.0 Device Authorization Grant, a so-called device flow, in which a user operates a smartphone to cause a printer to acquire an authentication token. In the device flow, a printer communicates with an authorization server device to acquire an authentication token from the authorization server device.

Prior Art Literature

Patent Literature

[0003]

Patent Literature 1

Patent Literature 2

Summary of the Invention

Problem to be Solved by the Invention

[0004] Various parameters are required for a communication device such as a printer to communicate with an authorization server device. For example, a configuration in which the communication device stores parameters in advance is conceivable. In this configuration, it is necessary to provide the communication device with a storage area for storing parameters in advance.

[0005] The present specification provides a technique for acquiring authentication information from an authentication server without providing a storage area for storing parameters in advance in the communication device.

Means for Solving the Problem

[0006] The communication device disclosed herein includes a first request transmission unit that, upon receiving a predetermined signal from a terminal device, transmits a parameter request to a specific server different from the authentication server, requesting parameters for communication with an authentication server, wherein the authentication server is configured to provide the communication device with authentication information for communication with a service server, and the service server is configured to provide a specific service to the user of the communication device; a parameter receiving unit that receives the parameters from the specific server as a response to the parameter request; and the parameters received from the specific server The system includes: a second request transmission unit that uses the authentication information to send an authentication information request to the authentication server requesting the authentication information; an authentication information receiving unit that receives the authentication information from the authentication server as a response to the authentication information request when a specific condition is met, such that the terminal device that is the source of the predetermined signal is logged in to either the authentication server or the service server using specific account information, and when the specific condition is not met, the authentication information is not received from the authentication server; and a data communication unit that uses the authentication information received from the authentication server to communicate target data with the service server.

[0007] According to the above configuration, the communication device receives parameters from a specific server and uses those parameters to send an authentication information request to the authentication server. In other words, the parameters only need to be stored on the specific server and do not need to be stored in the communication device beforehand. Authentication information can be obtained from the authentication server without providing a storage area in the communication device to store parameters in advance.

[0008] The computer program for realizing the above-mentioned communication device, and the computer-readable storage medium for storing the computer program, are also novel and useful. [Brief explanation of the drawing]

[0009] [Figure 1] Figure 1 is a conceptual diagram of the communication system. [Figure 2] Figure 2 is a block diagram of the multi-function machine. [Figure 3] Figure 3 is a block diagram of the parameter provisioning server. [Figure 4] Figure 4 is a sequence diagram showing the process for using the mail server. [Figure 5] Figure 5 is a continuation of Figure 4. [Figure 6] Figure 6 shows the screen transitions. [Modes for carrying out the invention]

[0010] (Configuration of communication system 2; Figure 1) Communication system 2 comprises a multifunction device 10, a terminal device 100, a parameter provision server 200, an authentication server 300, and a mail server 400. The multifunction device 10 is a multifunction device that includes printing and scanning functions. The multifunction device 10 is, for example, a peripheral device of the terminal device 100. Hereafter, the multifunction device 10 will be referred to as MFP10. The terminal device 100 is, for example, a smartphone, tablet PC, laptop PC, or desktop PC. The MFP10 and the terminal device 100 are connected to LAN4. LAN4 can be wired or wireless. The terminal device 100 communicates with the MFP10 via LAN4.

[0011] LAN4 is connected to the Internet 6. The Internet 6 is connected to a parameter provision server 200, an authentication server 300, and a mail server 400. A device connected to LAN4, such as a terminal device 100, communicates with a device connected to the Internet 6, such as the parameter provision server 200, via LAN4 and the Internet 6.

[0012] The mail server 400 is configured to provide email services to users. The authentication server 300 is configured to provide tokens to devices such as the MFP 10 for communication with the mail server. The business operator that installed the authentication server 300 is the same business operator that installed the mail server 400. However, in the modified version, the business operator that installed the authentication server 300 may be different from the business operator that installed the mail server 400.

[0013] The token provided by the authentication server 300 is, for example, a token compliant with OAuth. OAuth is an authentication method that uses a token instead of account information (i.e., username and password). The authentication server 300 provides the token to a device such as the MFP 10 with the consent of the user who holds the account information. The device uses the token to communicate with the mail server 400. In particular, the method of providing an OAuth-compliant token to a device that does not have a browser program, such as the MFP 10, is called a device flow. In this embodiment, the token is provided to the MFP 10 via a device flow.

[0014] There may be multiple providers offering email services. Therefore, there may also be multiple mail servers 400 and authentication servers 300. The number of mail servers 400 and authentication servers 300 is not limited to one; there may be two or more.

[0015] The parameter provision server 200 is configured to provide communication parameters for communication with the authentication server 300 to devices such as the MFP 10. The business operator that installed the parameter provision server 200 is the same as the vendor of the MFP 10, and this vendor is different from the business operator that installed the authentication server 300 and the mail server 400. With this configuration, the vendor of the MFP 10 can manage the parameter provision server 200, and this vendor can add or modify communication parameters at any time. In the modified example, the business operator that installed the parameter provision server 200 may be different from the vendor of the devices such as the MFP 10.

[0016] (Configuration of MFP 10; Figure 2) The MFP 10 comprises a print execution unit 12, a scan execution unit 14, a LAN interface 16, and a control unit 30. In the following description, an interface is abbreviated as "I / F".

[0017] The print execution unit 12 comprises a printing mechanism such as an inkjet method or a laser method. The scan execution unit 14 comprises a scanning mechanism such as a Charge Coupled Device (CCD) image sensor or a Contact Image Sensor (CIS). The LAN I / F 16 is an I / F for executing communication via the LAN 4, and is connected to the LAN 4.

[0018] The control unit 30 comprises a CPU 32 and a memory 34. The memory 34 stores a program 40 and a service table 50. The CPU 32 executes various processes in accordance with the program 40. The memory 34 is configured of a volatile memory, a non-volatile memory, or the like.

[0019] The service table 50 stores information for the MFP 10 to use an email service. The service table 50 stores a plurality of service IDs. A service ID is an ID for identifying a service. The service table 50 stores an email address, a protocol name, and a token in association with the service ID. The email address is an email address provided by the service identified by the service ID. The protocol name indicates a protocol for executing email communication using the email address. The token is information for authenticating email communication using the email address.

[0020] For example, the MFP 10 is configured to be capable of transmitting a scan email attached with scan data generated by the scan execution unit 14, using an email address stored in the service table 50.

[0021] (Configuration of parameter provision server 200: Figure 3) The parameter provision server 200 comprises a network interface 216 and a control unit 230. The network interface 216 is an interface for performing communication over the Internet 6 and is connected to the Internet 6.

[0022] The control unit 30 includes a CPU 232 and a memory 234. The memory 234 stores a program 240, an information table 250, and a parameter table 252. The CPU 232 performs various processes according to the program 240.

[0023] Information table 250 stores multiple service information entries. The service information includes a service ID, the service name of the service identified by that service ID, and a list of protocols available for that service.

[0024] Parameter table 252 stores multiple communication parameters. Each communication parameter is stored in parameter table 252 in association with a service ID. The communication parameters include devicecode_endpoint, token_endpoint, and client_id. devicecode_endpoint is the URL that indicates the destination for sending a code request to the authentication server 300 to request a code. token_endpoint is the URL that indicates the destination for sending a token request to the authentication server 300 to request a token. client_id identifies the client. Here, the client is the vendor of the device using the device flow, for example, the vendor of MFP10. client_id is provided to the vendor by the authentication server 300. Note that the communication parameters also include values ​​other than devicecode_endpoint, token_endpoint, and client_id. Other values ​​are fixed values ​​such as scope. scope includes a value that indicates the protocol used for email communication.

[0025] (Processing for using mail server 400; Figures 4, 5, and 6) Referring to Figures 4, 5, and 6, the process by which MFP10 utilizes the mail server 400 will be explained below. For ease of understanding, the actions performed by CPU32 according to program 40 will be described from the perspective of MFP10 rather than CPU32. Similarly, the parameter provision server 200 will be described from the perspective of parameter provision server 200 instead of CPU232. Furthermore, since all communication between MFP10 and other devices is performed via LANI / F16 and LAN4, the explanations "via LANI / F16" and "via LAN4" will be omitted below. Also, since all communication between parameter provision server 200 and other devices is performed via network I / F216 and Internet 6, the explanations "via network I / F216" and "via Internet 6" will be omitted below.

[0026] In addition to printing and scanning functions, the MFP10 also has a server function that allows it to operate as a server. In its server function, the MFP10 receives requests from a terminal device 100 acting as a client and provides the terminal device 100 with a settings screen. For example, a user can operate the settings screen provided by the MFP10 to change the settings of the MFP10, such as the network settings.

[0027] Terminal device 100 attempts to log in to the server function of MFP10 using account information for logging into the server function of MFP10. If terminal device 100 successfully logs in to the server function of MFP10 at T10, it sends an HTTP command to MFP10 at T12. HTTP is the Hyper Text Transfer Protocol. Note that the processes executed by terminal device 100 in Figures 4 and 5 are executed according to the browser program installed on terminal device 100.

[0028] In T14, terminal device 100 receives configuration screen information from MFP10 as a response to the HTTP command in T12.

[0029] In T16, the terminal device 100 displays a settings screen SC1 corresponding to the settings screen information. As shown in Figure 6, the settings screen SC1 includes a button BT1 for instructing the execution of a device flow in accordance with OAuth.

[0030] When terminal device 100 detects the selection of button BT1 in the settings screen SC1 at T20, it sends a service selection screen request to parameter provision server 200 at T22. The service selection screen request is a signal requesting service selection screen information corresponding to the service selection screen SC2 shown in Figure 6. The service selection screen request includes a call back URL. The call back URL indicates the destination for the information received from parameter provision server 200.

[0031] In T24, the terminal device 100 receives service selection screen information from the parameter provision server 200 as a response to a service selection screen request. The service selection screen information includes a list of service names stored in the information table 250. In T26, the terminal device 100 displays the service selection screen SC2. As shown in Figure 6, the service selection screen SC2 includes buttons for selecting one service from a plurality of services. For example, the service with the service name "ServiceA" is an email service provided by a first service provider, and the service with the service name "ServiceB" is an email service provided by a second service provider different from the first service provider. For example, the service selection screen SC2 includes a button BT2 for selecting the service name "ServiceA" and a button BT3 for selecting the service name "ServiceB". In this case, the mail server 400 provides the service with the service name "ServiceA".

[0032] When terminal device 100 detects the selection of button BT2 on the service selection screen SC2 at T30, it sends a selection notification to parameter provision server 200 at T32 indicating that the service name "ServiceA" has been selected.

[0033] When the parameter providing server 200 receives a selection notification from the terminal device 100 in T32, it retrieves the service ID "sss1" stored in association with the service name "ServiceA" indicated by the selection notification from the information table 250. In T34, the parameter providing server 200 sends the service ID "sss1" obtained from the information table 250 and the call back URL received from the terminal device 100 in T22 to the terminal device 100.

[0034] When terminal device 100 receives the service ID "sss1" and a call back URL from the parameter provision server 200 at T34, it accesses MFP10 at T36 using the call back URL. Then, terminal device 100 forwards the service ID "sss1" to MFP10.

[0035] When MFP10 receives the service ID "sss1" from terminal device 100 in T36, it transmits input screen information corresponding to input screen SC3 shown in Figure 6 to terminal device 100 in T38.

[0036] When terminal device 100 receives input screen information from MFP 10 at T38, it displays input screen SC3 at T40. As shown in Figure 6, input screen SC3 includes an input field for entering an email address and an input field for entering a protocol name indicating the protocol used for email address communication. In this case, the email server 400 already has the user account information of terminal device 100 registered. Furthermore, the email server 400 has already provided the email address MA1 for use by the user of terminal device 100.

[0037] When terminal device 100 detects input of email address MA1 and protocol name PL1 on input screen SC3 at T50, it sends email address MA1 and protocol name PL1 to MFP10 at T52. After executing the communication at T52, terminal device 100 displays polling screen SC4 (see Figure 6) indicating that it is waiting for a response from MFP10.

[0038] When MFP10 receives the email address MA1 and protocol name PL1 from terminal device 100 at T52, it sends a parameter request to parameter provider server 200 at T60 requesting communication parameters. The parameter request includes the service ID "sss1" received from terminal device 100 at T36 and the protocol name PL1 received from terminal device 100 at T52.

[0039] When the parameter provision server 200 receives a parameter request from the MFP10 at T60, it retrieves the communication parameter CP1 stored in association with the service ID "sss1" included in the parameter request from the parameter table 252. In this case, as shown in Figure 3, the communication parameter CP1 includes devicecode_endpoint "https: / / aaa.com / dc", token_endpoint "https: / / aaa.com / tk", client_id "xxx1", and other value V1. At T62, the parameter provision server 200 sends the communication parameter CP1 obtained from the parameter table 252 to the MFP10. As a result, the MFP10 can use the communication parameter CP1 to process the device flow from T70 onwards. If, for example, the service name "Service B" is selected by the user at T30, the parameter provision server 200 will receive a parameter request from the MFP10 at T60 that includes the service name "sss2". In this case, T62 sends the communication parameters stored in association with the service ID "sss2" to MFP10. This allows the MFP10 to be provided with communication parameters corresponding to the service selected by the user.

[0040] In T70, MFP10 sends a code request to authentication server 300 that includes the devicecode_endpoint "https: / / aaa.com / dc" contained in the communication parameter CP1 as the destination. The code request further includes the client_id "xxx1" contained in the communication parameter CP1 and the scope, which is a value indicating the protocol name PL1 selected in T50.

[0041] At T70, when the authentication server 300 receives a code request from the MFP10, it generates a device_code "ddd" and a user_code "uuu". The device_code "ddd" is a code for authenticating the device that sent the token request. The user_code "uuu" is a code for authenticating the user who accepts the provision of the token. At T72, the authentication server 300 stores the device_code "ddd" and user_code "uuu" in association with the client_id "xxx1" included in the communication parameter CP1. At T74, the authentication server 300 sends the device_code "ddd" and user_code "uuu" to the MFP10. Furthermore, at T74, the authentication server 300 sends a verification_uri to the MFP10. The verification_uri is a URI for receiving screen information corresponding to the input screen SC6 in Figure 6 from the authentication server 300.

[0042] When MFP10 receives device_code "ddd" etc. from authentication server 300 at T74, it transmits code screen information and verification_uri to terminal device 100 at T76. The code screen information corresponds to code screen SC5 shown in Figure 6. The code screen information includes user_code "uuu".

[0043] When terminal device 100 receives code screen information from MFP 10 at T76, it displays code screen SC5 at T78 instead of polling screen SC4. As shown in Figure 6, code screen SC5 displays the string indicating user_code "uuu". This allows the user of terminal device 100 to know user_code "uuu".

[0044] Furthermore, at T80, terminal device 100 sends an HTTP command to authentication server 300 that includes the verification_uri received from MFP10 at T76 as the destination. In response to the HTTP command, terminal device 100 receives screen information corresponding to input screen SC6 from authentication server 300. Then, at T80, terminal device 100 displays input screen SC6. Input screen SC6 is displayed in a different window from code screen SC5. As shown in Figure 6, input screen SC6 includes an input field for entering user_code.

[0045] Figure 5 shows the process that follows T82 in Figure 5. At T100 in Figure 5, MFP10 begins periodically sending token requests to authentication server 300 after receiving device_code "ddd" from authentication server 300 at T74. The token request includes token_endpoint "https: / / aaa.com / tk" included in the communication parameter CP1 as the destination. The token request further includes device_code "ddd".

[0046] When the authentication server 300 receives a token request from the MFP 10 at T100, it determines at T102 whether consent to provide the token has been obtained from the user. In this case, the timing of T100 is before the user_code "uuu" is entered into the input screen SC6 at T110. Therefore, at this point, the authentication server 300 determines at T102 that consent to provide the token has not been obtained from the user. At T102, the authentication server 300 does not provide the token to the MFP 10.

[0047] The user looks at the code screen SC5 displayed in T78 in Figure 4 and enters the user_code "uuu" displayed on the code screen SC5 into the input screen SC6.

[0048] When terminal device 100 detects that user_code "uuu" has been entered into input screen SC6 at T110, it sends user_code "uuu" to authentication server 300 at T112. As a result, authentication server 300 authenticates user_code "uuu" at T114. In this case, authentication of user_code "uuu" is successful.

[0049] If authentication for user_code "uuu" is successful, terminal device 100 receives account selection screen information corresponding to account selection screen SC7 in Figure 6 from authentication server 300 at T116. At T118, terminal device 100 displays account selection screen SC7.

[0050] In this case, terminal device 100 logs in to authentication server 300 using account information including account name "ac1". In a modified example, terminal device 100 may also log in to mail server 400 using account information including account name "ac1". Account name "ac1" is the account name assigned to the user of terminal device 100. As shown in Figure 6, account selection screen SC7 includes button BT4 for selecting the currently logged-in account name "ac1". Account selection screen SC7 further includes button BT5 for logging in with an account name different from the currently logged-in account name "ac1". In this case, the user selects button BT4 on account selection screen SC7.

[0051] When terminal device 100 detects the selection of button BT4 on the account selection screen SC7 at T120, it sends the account name "ac1" indicated by button BT4 to the authentication server 300 at T122. If the user selects button BT5 on the account selection screen SC7, terminal device 100 logs in to the authentication server 300 using an account name different from "ac1". Then, at T122, terminal device 100 sends this different account name to the authentication server 300. If terminal device 100 does not log in to the authentication server 300, the processes from T122 onwards are not executed, and the token is not provided to MFP 10. Thus, in OAuth, the token is provided to MFP 10 on the condition that terminal device 100 is logged in to either the authentication server 300 or the mail server 400 using predetermined account information.

[0052] When the authentication server 300 receives the account name "ac1" from the terminal device 100 at T122, at T124, it sends acceptance screen information corresponding to the acceptance screen SC8 in Figure 6 to the terminal device 100. As a result, at T126, the terminal device 100 displays the acceptance screen SC8.

[0053] The consent screen SC8 is used to obtain consent from a user who holds account information including the account name "ac1". The consent screen SC8 displays the name of the MFP10 firmware and the name of the MFP10 vendor, "AAA.Ltd", which is the client indicated by the client_id "xxx1" included in the T70 code request. The name of the MFP10 firmware is registered with the authentication server 300 in association with the client_id "xxx1". The consent screen SC8 includes a consent button BT6 that requests the user to consent to the provision of the token, and a cancel button BT7. In this case, the user selects the consent button BT6 on the consent screen SC8.

[0054] When terminal device 100 detects the selection of the accept button BT6 on the accept screen SC8 in T130, it sends an accept notification to authentication server 300 in T132 indicating that the accept button BT6 has been selected.

[0055] T140 is the same as T100. The timing of T140 is after the acceptance notification of T132 has been received. Therefore, the authentication server 300 determines in T142 that consent to the provision of the token has been obtained from the user.

[0056] In T144, the authentication server 300 authenticates the device_code "ddd" included in the token request. In this case, the authentication of device_code "ddd" is successful.

[0057] In the subsequent T146, the authentication server 300 generates token TK1. The authentication server 300 stores the generated token TK1, associating it with the logged-in account name "ac1". Here, token TK1 includes an access token and a refresh token. The refresh token is used to regenerate the access token.

[0058] At T148, the authentication server 300 sends token TK1 to the MFP10. As a result, at T150, the MFP10 stores token TK1 in the service table 50 of memory 34. As shown in Figure 2, token TK1 is stored in the service table 50 associated with the service ID "xxx1", email address MA1, and protocol name "PL1".

[0059] When MFP10 receives token TK1 from authentication server 300 at T148, it sends a completion notification to terminal device 100 at T152 indicating that the receipt of token TK1 is complete. As a result, terminal device 100 displays a completion screen SC9 at T154 indicating that the receipt of token TK1 is complete. The user can see the completion screen SC9 and know that the device flow executed according to the instructions at T20 in Figure 4 has been completed.

[0060] For example, when MFP10 detects a command to send a scanned email at T160, T162 sends a scanned email to the mail server 400 addressed to email address MA1 in the service table 50. The scanned email contains an access token from the service table 50. The mail server 400 uses the access token contained in the scanned email to authenticate the sender of the scanned email. In this case, the authentication is successful, and the mail server 400 stores the scanned email. The scanned email stored in the mail server 400 is viewed by a mail client configured with email address MA1.

[0061] (Effects of this embodiment) In this embodiment, the MFP10 receives the communication parameter CP1 from the parameter provision server 200 (T62 in Figure 4) and uses the communication parameter CP1 to send a token request to the authentication server 300 (T100 and T140 in Figure 5). In other words, the communication parameter CP1 only needs to be stored in the parameter provision server 200 and does not need to be stored in the MFP10 beforehand. The token TK1 can be obtained from the authentication server 300 without providing a storage area in the MFP10 to store the communication parameter CP1 in advance.

[0062] In particular, there may be multiple providers offering email services. When there are multiple such providers, the amount of data in the parameter table 252 increases as the number of providers increases. The storage capacity of the memory 34 of the MFP10 is smaller than the storage capacity of the memory 234 of the parameter provision server 200. The token TK1 can be obtained from the authentication server 300 without storing the parameter table 252 in the memory 34 of the MFP10, which has a relatively small storage capacity. Furthermore, even if the number of service providers increases after the MFP10 has been shipped from the vendor, the MFP10 can receive the communication parameters corresponding to the services of those providers from the parameter provision server 200, allowing the MFP10 user to use those services. The vendor can also simply register the communication parameters corresponding to the increased services in the parameter provision server 200.

[0063] (Correspondence) MFP10 and terminal device 100 are examples of "communication device" and "terminal device," respectively. Parameter provision server 200, authentication server 300, and mail server 400 are examples of "specific server," "authentication server," and "service server," respectively. The email service is an example of "specific service." Communication parameter CP1 is an example of "parameter." The HTTP command T12 in Figure 4 is an example of "predetermined signal." The parameter request T60 is an example of "parameter request." Service ID "sss1" and service ID "sss2" are examples of "first identification information" and "second identification information," respectively. user_code "uuu" and the code request T70 are examples of "user code" and "user code request," respectively. The token requests T100 and T140 and token TK1 in Figure 5 are examples of "authentication information request" and "authentication information," respectively. Account name "ac1" is an example of "specific account information." Scan data is an example of "target data." The input screen SC3, code screen SC5, and input screen SC6 in Figure 6 are examples of the "first input screen," "code screen," and "second input screen," respectively.

[0064] T60 and T62 in Figure 4 are examples of processes implemented by the "first request transmission unit" and the "parameter reception unit," respectively. T100 and T140 in Figure 5 are examples of processes implemented by the "second request transmission unit." T148 and T162 are examples of processes implemented by the "authentication information reception unit" and the "data communication unit," respectively.

[0065] Although specific examples of the present invention have been described in detail above, these are merely illustrative and do not limit the scope of the claims. The technology described in the claims includes various modifications and changes to the specific examples illustrated above. Modifications of the above embodiments are listed below.

[0066] (Variation 1) The "communication device" is not limited to the MFP10, but may also be a printer, scanner, PC, etc.

[0067] (Modification 2) The “specific service” is not limited to an email service, but may also be, for example, a service that provides print image content, a storage service that stores image data, or a Social Networking Service (SNS). Here, the content is, for example, a postcard image template. For example, if the “specific service” is a service that provides content, then content data is an example of “target data.” Also, for example, if the “specific service” is a storage service, then the input screen SC3 does not need to be displayed. In this modification, the “first input screen” can be omitted.

[0068] (Variation 3) Input screen SC3 does not need to include an input field for entering an email address. Also, input screen SC3 does not need to include an input field for entering a protocol name.

[0069] (Modification 4) If there is only one provider of email services, the parameter request in Figure 4 does not need to include the service ID "sss1". In this modification, the "identification information" can be omitted.

[0070] (Modification 5) Steps T70 to T82 in Figure 4 and T110 to T114 in Figure 5 do not need to be executed. In this modification, the "user code request" can be omitted.

[0071] (Modification 7) In the above embodiment, the processes shown in Figures 3 to 6 are realized by the CPUs 32 and 232 executing programs 40 and 240. Alternatively, any of the processes may be realized by hardware such as logic circuits.

[0072] Furthermore, the technical elements described herein or in the drawings demonstrate technical usefulness individually or in various combinations, and are not limited to the combinations described in the claims at the time of filing. In addition, the technologies illustrated herein or in the drawings achieve multiple objectives simultaneously, and achieving even one of these objectives constitutes technical usefulness in itself.

[0073] Even if, in the claims of this patent application, each claim depends on only some of the claims, it is not limited to the claim being dependent only on those specific claims. To the extent that it is not technically contradictory, each claim may be dependent on other claims that were not dependent at the time of application. That is, the technologies of each claim can be combined in various ways as follows: (Item 1) A communication device, A first request transmission unit, which, upon receiving a predetermined signal from a terminal device, transmits a parameter request to a specific server different from the authentication server, requesting parameters for communication with an authentication server, wherein the authentication server is configured to provide the communication device with authentication information for the communication device to communicate with a service server, and the service server is configured to provide a specific service to the user of the communication device, A parameter receiving unit receives the parameters from the specific server in response to the parameter request, A second request transmission unit that uses the parameters received from the specific server to send an authentication information request to the authentication server requesting the authentication information, An authentication information receiving unit that receives authentication information from the authentication server as a response to an authentication information request when the terminal device, which is the source of the predetermined signal, is logged in to either the authentication server or the service server using specific account information and certain conditions are met, and when the certain conditions are not met, the authentication information is not received from the authentication server. A data communication unit communicates with the service server and the target data using the authentication information received from the authentication server. A communication device equipped with the following features. (Item 2) The aforementioned specific service provides email to the user, The aforementioned communication device further, A first screen information transmission unit transmits input screen information corresponding to a first input screen to the terminal device, wherein the first input screen includes an input field for inputting protocol information indicating a protocol used for email communication, and the first screen information transmission unit A protocol information transmission unit that transmits the protocol information entered on the first input screen to the specific server, A communication device as described in item 1, comprising the features described in item 1. (Item 3) The communication device described in item 2, wherein the first input screen further includes an input field for entering the email address. (Item 4) The particular server stores a plurality of parameters, including a first parameter corresponding to the first service and a second parameter corresponding to the second service. The aforementioned communication device further, The terminal device includes an identification information receiving unit that receives identification information from the terminal device to identify the specific service selected in the terminal device, When the first identification information that identifies the first service is received, The first request transmission unit transmits the parameter request, including the first identification information, to the specific server. The parameter receiving unit receives the first parameter corresponding to the first service, When the second identification information that identifies the second service is received, The first request transmission unit transmits the parameter request, including the second identification information, to the specific server. The parameter receiving unit is a communication device according to any one of items 1 to 3, which receives the second parameter corresponding to the second service. (Item 5) The aforementioned authentication information is a token in accordance with OAuth, and is a communication device as described in any one of items 1 to 4. (Item 6) The aforementioned communication device further, A third request transmission unit that uses the parameters received from the specific server to send a user code request to the authentication server requesting a user code, A code receiving unit that receives the user code from the authentication server as a response to the user code request, A second screen information transmission unit that transmits code screen information corresponding to a code screen to the terminal device, The aforementioned code screen displays the user code received from the authentication server, The authentication server causes the terminal device to display a second input screen. The second input screen includes an input field for entering the user code, The authentication server performs authentication of the user code entered on the second input screen. The second screen information transmission unit, Equipped with, The communication device according to any one of items 1 to 5, wherein the specific condition is that the terminal device logs in to either the authentication server or the service server using the specific account information, and the authentication by the authentication server is successful. (Item 7) The first request transmission unit is a communication device according to any one of items 1 to 6, which transmits the parameter request to the specific server after the terminal device has logged into the communication device. (Item 8) Unlike the authentication server, the aforementioned service server, The business operator that installed the service server is the same as the business operator that installed the authentication server, and the communication device is one of the items described in any one of items 1 to 7. (Item 9) The communication device described in any one of items 1 to 8, wherein the operator who installed the aforementioned specific server is the same as the vendor of the aforementioned communication device. (Item 10) A computer program for a communication device, The aforementioned computer program controls the computer of the communication device in the following parts, namely: A first request transmission unit, which, upon receiving a predetermined signal from a terminal device, transmits a parameter request to a specific server different from the authentication server, requesting parameters for communication with an authentication server, wherein the authentication server is configured to provide authentication information for the communication device to communicate with a service server, and the service server is configured to provide a specific service to the user of the communication device, A parameter receiving unit receives the parameters from the specific server in response to the parameter request, A second request transmission unit that uses the parameters received from the specific server to send an authentication information request to the authentication server requesting the authentication information, An authentication information receiving unit that receives authentication information from the authentication server as a response to an authentication information request when the terminal device, which is the source of the predetermined signal, is logged in to either the authentication server or the service server using specific account information and certain conditions are met, and when the certain conditions are not met, the authentication information is not received from the authentication server. A data communication unit communicates with the service server and the target data using the authentication information received from the authentication server. A computer program that functions as such. [Explanation of Symbols]

[0074] 2: Communication Systems 4: LAN 6: Internet 10: MFP 12: Print execution unit 14: Scan execution unit 16 :LANI / F 30: Control Unit 32:CPU 34: Memory 40: Program 50: Service Table 100: Terminal device 200: Parameter provider server 216: Network I / F 230: Control Unit 232:CPU 234: Memory 240: Program 250: Information Table 252: Parameter Table 300: Authentication Server 400: Mail Server BT1, BT2, BT3, BT4, BT5: Buttons BT6: Accept button BT7: Cancel button CP1: Communication parameters MA1: Email Address PL1: Protocol name SC1: Settings screen SC2: Service Selection Screen SC3: Input screen SC4: Polling screen SC5: Code Screen SC6: Input screen SC7: Account Selection Screen SC8: Promise Screen SC9: The screen is finished. TK1:トークン

Claims

1. A communication device, A first request transmission unit, which, upon receiving a predetermined signal from a terminal device, transmits a parameter request to a specific server different from the authentication server, requesting parameters for communication with an authentication server, wherein the authentication server is configured to provide the communication device with authentication information for the communication device to communicate with a service server, and the service server is configured to provide a specific service to the user of the communication device, A parameter receiving unit receives the parameters from the specific server in response to the parameter request, A second request transmission unit sends an authentication information request to the authentication server, which requests the authentication information using the parameters received from the specific server. An authentication information receiving unit that receives authentication information from the authentication server as a response to an authentication information request when the terminal device, which is the source of the predetermined signal, is logged in to either the authentication server or the service server using specific account information and certain conditions are met, and when the certain conditions are not met, the authentication information is not received from the authentication server. A data communication unit communicates with the service server and the target data using the authentication information received from the authentication server. A communication device equipped with the following features.

2. The aforementioned specific service provides email to the user, The aforementioned communication device further, A first screen information transmission unit transmits input screen information corresponding to a first input screen to the terminal device, wherein the first input screen includes an input field for inputting protocol information indicating a protocol used for email communication, and the first screen information transmission unit A protocol information transmission unit that transmits the protocol information entered on the first input screen to the specific server, A communication device according to claim 1, comprising:

3. The communication device according to claim 2, wherein the first input screen further includes an input field for entering the email address.

4. The particular server stores a plurality of parameters, including a first parameter corresponding to the first service and a second parameter corresponding to the second service. The aforementioned communication device further, The terminal device includes an identification information receiving unit that receives identification information from the terminal device to identify the specific service selected in the terminal device, When the first identification information that identifies the first service is received, The first request transmission unit transmits the parameter request, including the first identification information, to the specific server. The parameter receiving unit receives the first parameter corresponding to the first service, When the second identification information that identifies the second service is received, The first request transmission unit transmits the parameter request, including the second identification information, to the specific server. The communication device according to any one of claims 1 to 3, wherein the parameter receiving unit receives the second parameter corresponding to the second service.

5. The communication device according to any one of claims 1 to 3, wherein the authentication information is a token in accordance with OAuth.

6. The aforementioned communication device further, A third request transmission unit that uses the parameters received from the specific server to send a user code request to the authentication server requesting a user code, A code receiving unit that receives the user code from the authentication server as a response to the user code request, A second screen information transmission unit that transmits code screen information corresponding to a code screen to the terminal device, The aforementioned code screen displays the user code received from the authentication server, The authentication server causes the terminal device to display a second input screen. The second input screen includes an input field for entering the user code, The authentication server performs authentication of the user code entered on the second input screen. The second screen information transmission unit, Equipped with, The communication device according to any one of claims 1 to 3, wherein the specific condition is that the terminal device logs in to either the authentication server or the service server using the specific account information, and the authentication by the authentication server is successful.

7. The communication device according to any one of claims 1 to 3, wherein the first request transmission unit transmits the parameter request to the specific server after the terminal device has logged in to the communication device.

8. Unlike the authentication server, the aforementioned service server, The communication device according to any one of claims 1 to 3, wherein the business operator that installed the service server is the same as the business operator that installed the authentication server.

9. The communication device according to any one of claims 1 to 3, wherein the business operator that installed the aforementioned specific server is the same as the vendor of the communication device.

10. A computer program for a communication device, The aforementioned computer program controls the computer of the communication device in the following parts, namely: A first request transmission unit, which, upon receiving a predetermined signal from a terminal device, transmits a parameter request to a specific server different from the authentication server, requesting parameters for communication with an authentication server, wherein the authentication server is configured to provide authentication information for the communication device to communicate with a service server, and the service server is configured to provide a specific service to the user of the communication device, A parameter receiving unit receives the parameters from the specific server in response to the parameter request, A second request transmission unit sends an authentication information request to the authentication server, which requests the authentication information using the parameters received from the specific server. An authentication information receiving unit that receives authentication information from the authentication server as a response to an authentication information request when the terminal device, which is the source of the predetermined signal, is logged in to either the authentication server or the service server using specific account information and certain conditions are met, and when the certain conditions are not met, the authentication information is not received from the authentication server. A data communication unit communicates with the service server and the target data using the authentication information received from the authentication server. A computer program that functions as such.

Citation Information

Patent Citations

  • Network device

    JP2010108396A

  • Communication device, communication method, and program

    JP2017135519A

  • Image forming apparatus, image communication method and program thereof

    JP2018055347A

  • Authorization server and resource provision system

    JP2018084979A

  • Relay server, authentication system, relay method, and program

    JP2021140338A