Image forming method
3 claims: 2 independent, 1 dependent
- 1Login username for user authenticationPassword entered in addition toThe authentication control unit that accesses the authentication server and performs the authentication process to acquire the display user name associated with the login user name from the authentication server, and the display user name instead of the login user name. Has a log management unit that records logs that are records of operations usingAnd The authentication control unit acquires a plurality of display user name candidates from the authentication server during the authentication process, and obtains a plurality of candidates for the display user name. It has a display user name setting unit that registers a value set by a user's selection input from the plurality of acquired display user names as a display user name in the log management unit. An image forming apparatus characterized in that. ユーザ認証の為にログインユーザ名に加えて入力されたパスワードを伴って認証サーバにアクセスして認証処理を行い、前記認証サーバから前記ログインユーザ名と関連付けられた表示用ユーザ名を取得する認証制御部と、 前記ログインユーザ名に代えて前記表示用ユーザ名を用いて動作の記録であるログを記録するログ管理部とを有し、 前記認証制御部は、前記認証処理時に前記認証サーバから前記表示用ユーザ名の候補を複数取得し、 前記複数取得された表示用ユーザ名からユーザの選択入力によって設定された値を前記ログ管理部に対して表示用ユーザ名として登録する表示用ユーザ名設定部を有する ことを特徴とする画像形成装置。
- 3An image forming system having an authentication server for user authentication and an image forming device that accesses the authentication server and performs authentication processing, and the image forming device is a login user name for the user authentication.Password entered in addition toThe authentication control unit that accesses the authentication server and performs the authentication process to acquire the display user name associated with the login user name from the authentication server, and the display user instead of the login user name. The authentication server has a log management unit that records a log that is a record of operations using a name, and the authentication server includes a user management control unit that performs authentication processing based on the login user name, and the login user name and the display. It has a display user name management unit that records and holds the user name in association with the user name and transmits the display user name to the authentication control unit when the user is authenticated.And The authentication control unit acquires a plurality of display user name candidates from the authentication server during the authentication process, and obtains a plurality of candidates for the display user name. The image forming apparatus has a display user name setting unit that registers a value set by a user's selection input from a plurality of acquired display user names as a display user name in the log management unit. An image forming system characterized by this. ユーザ認証の為の認証サーバと前記認証サーバにアクセスして認証処理を行う画像形成装置とを有する画像形成システムであって、 前記画像形成装置は、前記ユーザ認証の為にログインユーザ名に加えて入力されたパスワードを伴って前記認証サーバにアクセスして認証処理を行い、前記認証サーバから前記ログインユーザ名と関連付けられた表示用ユーザ名を取得する認証制御部と、 前記ログインユーザ名に代えて前記表示用ユーザ名を用いて動作の記録であるログを記録するログ管理部とを有し、 前記認証サーバは、前記ログインユーザ名に基づいて認証処理を行うユーザ管理制御部と、前記ログインユーザ名と前記表示用ユーザ名とを関連付けて記録保持し、前記ユーザ認証された場合に、前記表示用ユーザ名を前記認証制御部に送信する表示用ユーザ名管理部とを有し、 前記認証制御部は、前記認証処理時に前記認証サーバから前記表示用ユーザ名の候補を複数取得し、 前記画像形成装置は、前記複数取得された表示用ユーザ名からユーザの選択入力によって設定された値を前記ログ管理部に対して表示用ユーザ名として登録する表示用ユーザ名設定部を有する ことを特徴とする画像形成システム。
Independent claims2
14 paragraphs, as filed
Regarding the log recording of the image forming apparatus, it relates to a technology for protecting personal information important for security such as a login user ID.
In electronic devices such as image forming devices, user authentication is performed to identify the operator. When a job is executed after user authentication, the job record is saved in a file called a log, but in the conventional log of the method of authenticating with the image forming device alone, the "login user" used at the time of authentication The "ID" is not recorded in the log as it is, but the "display user name" that is recorded in the image forming device in association with the "login user ID" and does not pose a security problem even if seen by others is recorded. It is a mechanism to log in. By this method, a method of protecting the "login user ID", which is important for security, has been taken.
However, when network authentication is performed using a server instead of the image forming device alone, since there is no authentication information in the image forming device, it is possible to record in the log using the "display user name" as described above. It cannot be done, and the "login user ID" when accessing the authentication server is recorded in the log, which poses a security problem.
As a conventional technique, there is a method of recording a user name and time information in job status information and job history information in order to identify a job sent by a user, and providing a system that allows the user to uniquely identify the job (patented). See Reference 1).
However, with this method, when a user logged in with network authentication executes a job, the "logged-in user ID" may be used or not displayed as the user name in the job history. The former has room for improvement in terms of security, and the latter method has a problem that it is difficult to identify who the job is.
<p><patcit num="1"><text>Japanese Unexamined Patent Publication No. 2008-28780</text></patcit></p>
<p> The problem to be solved is to avoid that the user of the job can be identified and the "login user ID" is recorded in the log that records the execution of the job when the user is authenticated through the network in the image forming apparatus. This is the point that I couldn't do.</p>
<p> The image forming apparatus of the present invention has a login user name for user authentication.<u style="single">Password entered in addition to</u>The authentication control unit that accesses the authentication server and performs the authentication process to acquire the display user name associated with the login user name from the authentication server, and the display user name instead of the login user name. Has a log management unit that records logs that are records of operations using<u style="single">Then, the authentication control unit acquires a plurality of candidates for the display user name from the authentication server at the time of the authentication process, and logs the value set by the user's selection input from the plurality of acquired display user names. It has a display user name setting unit that is registered as a display user name in the management unit.</u>It is characterized by that.</p><p> Further, the authentication control unit of the image forming apparatus of the present invention generates a user identifier based on the login user name after the authentication process, and uses the user identifier instead of the login user name in the subsequent job execution process. May be a feature.</p><p> The image forming system of the present invention is an image forming system having an authentication server for user authentication and an image forming device that accesses the authentication server and performs an authentication process, and the image forming device is the user authentication. Login username for<u style="single">Password entered in addition to</u>The authentication control unit that accesses the authentication server and performs the authentication process to acquire the display user name associated with the login user name from the authentication server, and the display user instead of the login user name. The authentication server has a log management unit that records a log that is an operation record using a name, and the authentication server includes a user management control unit that performs authentication processing based on the login user name, and the login user name and the display. It has a display user name management unit that records and holds the user name in association with the user name and transmits the display user name to the authentication control unit when the user is authenticated.<u style="single">Then, the authentication control unit acquires a plurality of candidates for the display user name from the authentication server at the time of the authentication process, and the image forming apparatus is set by the user's selection input from the plurality of acquired display user names. It has a display user name setting unit that registers the value as a display user name in the log management unit.</u>It is characterized by that.</p>
<p> The image forming apparatus of the present invention has a login user name for user authentication.<u style="single">Password entered in addition to</u>The authentication control unit that accesses the authentication server and performs the authentication process to acquire the display user name associated with the login user name from the authentication server, and the display user name instead of the login user name. Has a log management unit that records logs that are records of operations using<u style="single">Then, the authentication control unit acquires a plurality of candidates for the display user name from the authentication server at the time of the authentication process, and logs the value set by the user's selection input from the plurality of acquired display user names. It has a display user name setting unit that is registered as a display user name in the management unit.</u>It is characterized by that.</p><p> Therefore, the login user name is not recorded in the log, and the possibility that the login user name, which is important for security, is exposed is greatly suppressed, and the security is enhanced.</p><p><u style="single"> In addition, since the optimum display user name can be selected according to the user's environment, convenience such as when viewing logs is greatly improved.</u></p><p><u style="single"> Also</u>, Authentication security is enhanced by accompanying a password at the time of authentication.</p><p> Further, the authentication control unit of the image forming apparatus of the present invention generates a user identifier based on the login user name after the authentication process, and uses the user identifier instead of the login user name in the subsequent job execution process. May be a feature.</p><p> Therefore, even when exchanging information in the image forming apparatus main body, since the user identifier is used after the login user name is required, the confidentiality of protecting the login user name is further increased.</p><p> The image forming system of the present invention is an image forming system having an authentication server for user authentication and an image forming device that accesses the authentication server and performs an authentication process, and the image forming device is the user authentication. Login username for<u style="single">Password entered in addition to</u>The authentication control unit that accesses the authentication server and performs the authentication process to acquire the display user name associated with the login user name from the authentication server, and the display user instead of the login user name. The authentication server has a log management unit that records a log that is an operation record using a name, and the authentication server includes a user management control unit that performs authentication processing based on the login user name, and the login user name and the display. It has a display user name management unit that records and holds the user name in association with the user name and transmits the display user name to the authentication control unit when the user is authenticated.<u style="single">Then, the authentication control unit acquires a plurality of candidates for the display user name from the authentication server at the time of the authentication process, and the image forming apparatus is set by the user's selection input from the plurality of acquired display user names. It has a display user name setting unit that registers the value as a display user name in the log management unit.</u>It is characterized by that.</p><p> Therefore, the login user name is not recorded in the log, and the possibility that the login user name, which is important for security, is exposed is greatly suppressed, and the security is enhanced.</p>
<figref num="1">It is a functional block diagram of the image forming apparatus of the Example of this invention (Example 1).</figref><figref num="2">It is a sequence diagram which shows the operation flow of the image forming apparatus of the Example of this invention (Example 1).</figref><figref num="3">It is a functional block diagram of the image forming apparatus of the Example of this invention (Example 2).</figref><figref num="4">It is a sequence diagram which shows the operation flow of the image forming apparatus of the Example of this invention (Example 2).</figref><figref num="5">This is an example of a user interface screen for designating a display user name of the image forming apparatus of the embodiment of the present invention (Example 2).</figref>
In the image forming apparatus that authenticates the user through the network, the purpose of avoiding that the login user ID is recorded in the log is to prepare a display user name associated with the login user ID in the external authentication server and perform user authentication. Then, the display user name is passed to the image forming apparatus, and when the image forming apparatus records the log, the display user name is recorded instead of the login user ID.
<p> The image forming apparatus and the image forming system according to the first embodiment of the present invention will be described below.</p><p> [Constitution] FIG. 1 is a functional block diagram of an image forming apparatus 101, an external authentication server (authentication server) 201, and an LDAP (Lightweight Directory Access Protocol) server 301.</p><p> The image forming apparatus 101 includes a UI unit 111, a job control unit 113, an authentication / authorization control unit (authentication control unit) 115, a job status management unit 117, a job history management unit (log management unit) 119, and a network control unit 121. ..</p><p> The UI unit (user interface unit) 111 is a functional unit that handles input / output with and from the user. The UI unit 111 has an output device such as a display panel for displaying and outputting, and an input device such as a key and a touch panel integrated with the display panel to display to the user and input from the user. Accept.</p><p> The job control unit 113 is a functional unit that controls jobs of the image forming apparatus 101. The job control unit 113 receives the operation instruction received by the UI unit 111, and executes the job according to the operation instruction.</p><p> The authentication / authorization control unit (authentication control unit) 115 makes an authentication request to the external authentication server (authentication server) 201 for the login request from the user received by the UI unit 111. Authentication methods such as NTLM authentication and kerberos authentication are used for authentication.</p><p> The job status management unit 117 manages the status of the job executed and controlled by the job control unit 113. In response to job status inquiries from other functional units (for example, UI unit 111), the job status is checked and answered.</p><p> The job history management unit (log management unit) 119 records and saves the history (log) of job execution. The information to be recorded is the job name, job content, job owner name, and the like. Further, it may be said that the job start time / end time, the job execution status (whether the job ends normally or abnormally, and the error code in the case of abnormal end) are recorded. As the job owner name, the display user name is recorded instead of the login user name.</p><p> The network control unit 121 is a functional unit for communicating with the external authentication server 201 and the LDAP server (authentication server) 301.</p><p> The external authentication server (authentication server) 201 has each function unit of the user management control unit 211 and the network control unit 213.</p><p> The user management control unit 211 records the login ID and password of the user management control unit 211 itself in response to the login authentication request accompanied by the login ID and password data from the electronic device such as the image forming apparatus 101. It collates and authenticates if it matches. When authentication is performed, a permit certificate is issued to the authentication requester.</p><p> The network control unit 213 is a functional unit for communicating with the image forming apparatus 101.</p><p> The LDAP (Lightweight Directory Access Protocol) server 301 is a server that has a directory database and responds to inquiries by the Lightweight Directory Access Protocol from network devices such as an image forming apparatus 101.</p><p> The LDAP server (authentication server) 301 has each function unit of the address book management control unit (display user name management unit) 311 and the network control unit 313.</p><p> The address book management control unit (display user name management unit) 311 has a directory database, and needs necessary information (for example, displayUN) and e-mail in response to an inquiry from the image forming apparatus 101. Get the address (E-Mail) and fax number (faxNumber) from the directory database and reply. In order to maintain security, this inquiry is answered only when the inquiry destination searches for the user attribute information with the authorization certificate obtained from the external authentication server 201.</p><p> [Operation flow; Sequence] FIG. 2 is a sequence diagram showing an operation flow of the image forming apparatus 101 according to the first embodiment of the present invention. Each sequence will be described below in order.</p><p> S11: When the panel user inputs the "login ID" and the "login password" to perform the login operation, the UI unit 111 of the image forming apparatus 101 accepts the input.</p><p> The input received in S13: S11 is passed to the authentication / authorization control unit 115.</p><p> S15, S17: The authentication / authorization control unit 115 determines that the authentication is network authentication. In the case of network authentication, the input is transmitted to the external authentication server 201 through the network control unit 121 to make an authentication request. If the authentication is performed, the authorization certificate is obtained from the external authentication server 201.</p><p> S19, S21: When there is an authentication authorization response (successful acquisition of authorization certificate) from the external authentication server 201, the authentication / authorization control unit 115 passes through the network control unit 121 to the external address book server (LDAP server) 301. For, the user attribute information of the logged-in user (display user name, E-mail address, FAX number, etc.) is acquired.</p><p> S31: The UI unit 111 of the image forming apparatus 101 receives a job start from the user.</p><p> S33: The authentication / authorization control unit 115 that receives the job execution instruction from the UI unit 111 acquires the user identifier from the authentication / authorization control unit 115. The user identifier is temporarily generated by the authentication / authorization control unit based on the loginID (login user name). From this step onward, the generated user identifier is used in place of the loginID, further increasing the security of the loginID.</p><p> S35: The job input and operated by the UI unit 111 is passed to the job control unit 113.</p><p> S37: The job control unit executes the job.</p><p> S39: After the job processing is completed, the authentication / authorization control unit 115 acquires the "display user name" (displayUN in S21) acquired in S21 based on the user identifier.</p><p> S41: The job history management unit (log management unit) 119 saves the job history (log). At this time, the loginID (login user name), user identifier, and the like are not recorded in the log, and the above-mentioned "display user name" is recorded as the information indicating the job owner. In addition, the job ID, job name, job type, etc. are recorded in the log. Further, the job start time, the job end time, the job status, and the like may be recorded.</p><p> [Effect of Examples] Even during network authentication, the "login user ID", which is important for security, is not recorded and is protected by the method of recording the job using the "display user name" in the job log and job status.</p><p> Furthermore, in general, it is difficult to match the actual person name with the "login user ID", so it is often the case that the user cannot be identified immediately by looking at the log. The owner of the job can be identified immediately.</p><p> After the "login user ID" is used in the steps from S11 to S21, the user identifier generated in S33 is used, so the possibility that the "login user ID" is leaked is further reduced and the security of the information is high. Will increase.</p>
<p> The image forming apparatus of Example 2 of the present invention will be described below.</p><p> In the image forming apparatus of the second embodiment, in addition to the functions of the image forming apparatus of the first embodiment, the display user name can be further selected from a plurality of candidates.</p><p> In the first embodiment, the "display user name" is acquired from the directory database recorded by the address book management unit 311 of the LDAP server 301, but the "display user name" is set to which attribute value depending on the user's operating environment. It may be different. Therefore, in the image forming apparatus of the second embodiment, it is possible to select which attribute information to be used as the "display user name" among the attribute information of a plurality of users acquired from the directory database, thereby creating a user environment. At the same time, it was decided to display appropriate attribute values.</p><p> [Constitution] FIG. 2 is a functional block diagram of the image forming apparatus 101 of the second embodiment of the present invention. The image forming apparatus 101 of the second embodiment has a system setting value management unit 131 shown in FIG. 2 in addition to each functional block shown in the functional block diagram shown in FIG. In the configuration of the second embodiment, the functions of the system setting value management unit (display user name setting unit) 131 will be mainly described, and the differences regarding other functional blocks will also be described at the same time.</p><p> The system setting value management unit 131 (display user name setting unit) makes it possible to select the display user name to be recorded in the log from the user attribute values acquired from the LDAP server at the time of user authentication. This selection is made by the UI unit 111 accepting the input from the user. Examples of selected candidates are shown in Table 1 below.</p><p><tables num="1"><img file="JP5116715B2_D0001.tif" /></tables></p><p> As shown in Table 1, a display user name with a preset column may be selected as the display user name as in the first embodiment, or another common name (last name), first name, surname, employee. It may be a method of selecting a number or the like instead.</p><p> Figure 5 shows an example of the screen for this selection input.</p><p> When selecting each item in Table 1 above as the display user name, check the corresponding check box. In addition, when recording an e-mail address or fax number in the log, it is possible by putting a check mark in each corresponding check box. In FIG. 5, "employee number" is selected as the display user name, and "e-mail address" and "telephone number" (not shown in Table 1 for omission) are recorded in the log.</p><p> [Operation flow; Sequence] FIG. 4 shows a sequence diagram showing an operation flow of the image forming apparatus 101 of the second embodiment. The flow of operation will be described with reference to FIG.</p><p> Since the flow from S51 to S57 is the same as the flow from S11 to S17 shown in FIG. 2 of the first embodiment, the description thereof will be omitted.</p><p> S59: The authentication / authorization control unit 115 acquires the search attribute information from the system setting value management unit 131. The acquired search attribute information is a user attribute value as shown in Table 1 above. At this time, the display user name candidates selected and input using the user interface screen as shown in FIG. 5 in advance are recorded in the authentication / authorization control unit 115.</p><p> S61, S63: Acquire the above search attribute information from LDAP server 301.</p><p> The operation of S71 to S77 is the same as the operation of S31 to S37, so it is omitted.</p><p> S79: In order to record the job history, access the authentication / authorization control unit 115 and acquire the display user name candidate selected and input in S59.</p><p> S81: The job history management unit 119 records the job log using the display user name selected in the previous step.</p><p> The log is recorded using the display user name candidates selected and input by the above series of operations.</p><p> [Effect of Examples] Since the search attribute as the display user name can be set by the user's selection input, the log is recorded based on the information suitable for the user environment, and the convenience when viewing the log is improved.</p><p> [Other] In the examples of the present invention, the recording of the job log (job log) has been described, but it goes without saying that the present invention can be applied not only to the job log but also to other logs such as an authentication log. ..</p><p> In the embodiment of the present invention, the authentication server is divided into an external authentication server 201 for the user authentication function and an LDAP server 301 for holding the user name record for display, but these are combined into the same server device. It may be in a form in which two server functions are installed. Further, one authentication server may be configured to have both the functions of the user management control unit 211 and the address book management control unit 313.</p>
101 Image forming apparatus (Examples 1 and 2) 111 UI (User Interface) Part (Examples 1 and 2) 113 Job Control Unit (Examples 1 and 2) 115 Authentication / Authorization Control Unit (Authentication Control Unit) (Examples 1 and 2) 117 Job Status Management Department (Examples 1 and 2) 119 Job History Management Department (Log Management Department) (Examples 1 and 2) 121 Network Control Unit (Examples 1 and 2) 131 System setting value management unit (display user name setting unit) (Example 2) 201 External Authentication Server (Authentication Server) (Examples 1 and 2) 211 User Management Control Unit (Examples 1 and 2) 213 Network control unit (Examples 1 and 2) 301 LDAP server (authentication server) (Examples 1 and 2) 311 Address book management control unit (display user name management unit) (Examples 1 and 2) 313 Network Control Unit (Examples 1 and 2)
2 sheets
Sheet 1 Sheet 2
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| JP2008028753A | Cites | Japan |
| JP2009043018A | Cites | Japan |
| JP2003006162A | Cites | Japan |
| JP2008191857A | Cites | Japan |
| JP2007087002A | Cites | Japan |
5 members in 3 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2009071242 | Japan | A | |
| JP20090071242 | – | – | – |
Members5
| Document | Office | Kind | |
|---|---|---|---|
| CN101848103A | China | A | |
| US2010251354A1 | United States of America | A1 | |
| JP2010224857A | Japan | A | |
| JP5116715B2This record | Japan | B2 | |
| US8799995B2 | United States of America | B2 |
12 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 5116715
- Publication, DOCDB
- 5116715
- Publication, EPODOC
- JP5116715B
- Application
- 71242
- Application, DOCDB
- 2009071242
- Application, EPODOC
- JP20090071242
Titles2
- English
- An image forming device and an image forming system
- Japanese
- ????????????????
Classification
- CPC, 3
- H04L63/102
- G06F21/78
- H04L63/0892
- IPC, 6
- G06F21 62
- B41J29 00
- B41J29 38
- G06F3 12
- G06F21 31
- H04N1 00
