Information processing system and program
The information processing system addresses increased load and unnecessary access denials in encrypted DNS communications by associating destination information with operation and user permissions, enhancing access management efficiency.
Patent Information
- Application Number
- JP2024045201
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-21
- Publication Date
- 2025-10-03
AI Technical Summary
Existing systems face increased load and unnecessary access denials when determining access permissions for encrypted DNS communications, as they rely solely on destination information without considering user operations or electronic certificates.
An information processing system that associates destination information with operation and user permissions, allowing access only when all conditions are met, thereby reducing load and preventing unnecessary denials.
The system effectively manages access permissions by reducing decision-making load and preventing unnecessary access denials by considering both destination and operation/user information.
Smart Images

Figure 2025145163000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to an information processing system and a program. [Background technology]
[0002] Since name resolution by DNS (Domain Name System) targets plain text, security issues can arise. To address this, DoH (DNS over HTTPS), which utilizes HTTPS (Hybertext Transfer Protocol Secure) encryption, is sometimes used.
[0003] Patent Document 1 describes a system that extracts a domain name from a DNS request and determines whether or not to permit access to the domain name based on a policy.
[0004] Patent Document 2 describes a packet filtering device that, when a TLS (Transport Layer Security) connection is made, acquires a digital certificate from a server, and if a host name extracted from the digital certificate is included in the filtering condition information, updates IP address information using the destination IP address of the connection packet. The packet filtering device determines whether or not to allow a communication packet to pass based on whether or not the destination IP address of the communication packet sent from a terminal device is included in the IP address information. [Prior art documents] [Patent documents]
[0005] [Patent Document 1] Special Publication No. 2014-519751 [Patent Document 2] Japanese Patent Application Laid-Open No. 2017-135622 Summary of the Invention [Problem to be solved by the invention]
[0006] However, because DoH also encrypts destination information, systems that typically use fully qualified domain names (FQDNs), an example of destination information, to determine whether or not to allow access cannot determine whether or not to allow access. To address DNS encryption, it is conceivable to determine whether or not to allow access by analyzing the TLS connections of all communications, but this could increase the load on the system that determines whether or not to allow access. Furthermore, if access is determined solely based on destination information such as domain names, access may be denied even when no security issues arise.
[0007] The object of the present invention is to reduce the increase in the load required for making a decision compared to when an electronic certificate is used to determine whether access should be permitted, and to prevent unnecessary denial of access to the system being accessed compared to when access should be permitted based solely on information indicating the destination. [Means for solving the problem]
[0008] The invention of claim 1 is an information processing system having a processor and a memory, wherein the memory stores information indicating the destination of a system to be accessed and information indicating operations prohibited for the system to be accessed, in association with each other; when a system to be accessed and an operation to be performed on the system are specified by a user, if the information indicating the destination of the system specified by the user and the information indicating the operation specified by the user are not associated and stored in the memory, the processor requests a system to perform name resolution based on the information indicating the destination of the system specified by the user, accesses the system according to the address obtained in response to the request, and if the information indicating the destination of the system specified by the user and the information indicating the operation specified by the user are associated and stored in the memory, the processor does not request the system to perform name resolution based on the information indicating the address of the system specified by the user.
[0009] The invention of claim 2 is the information processing system of claim 1, wherein the memory further stores information indicating the destination of the system to be accessed, information indicating operations that are prohibited on the system to be accessed, and information indicating the user who is prohibited from performing the operations, in association with each other; if the information indicating the destination of the system specified by the user, the information indicating the operation specified by the user, and information indicating the user are not associated and stored in the memory, the processor requests a system to perform name resolution based on the information indicating the destination of the system specified by the user and accesses the system according to the address obtained in response to the request; and if the information indicating the destination of the system specified by the user, the information indicating the operation specified by the user, and information indicating the user are associated and stored in the memory, the processor does not request a system to perform name resolution based on the information indicating the address of the system specified by the user.
[0010] The invention of claim 3 is an information processing system as described in claim 1, wherein information indicating the destination of the system to be accessed, information indicating operations prohibited for the system to be accessed, and the address of the system to be accessed are linked and managed by a management system, and the processor further acquires the information indicating the destination of the system to be accessed, information indicating operations prohibited for the system to be accessed, and the address of the system to be accessed, which are linked to each other, from the management system and stores them in the memory, and the processor further requests the management system to change the linking between the information indicating the destination of the system to be accessed, the information indicating operations prohibited for the system to be accessed, and the address of the system to be accessed, if the address stored in the memory linked to the information indicating the destination of the system specified by the user is different from the address acquired by name resolution based on the information indicating the destination of the system specified by the user.
[0011] The invention of claim 4 is a program that causes a computer having a memory that stores information indicating the destination of a system to be accessed and information indicating operations that are prohibited on the system to be accessed in association with each other, to operate in the following manner: when a system to be accessed and an operation to be performed on that system are specified by a user, if the information indicating the destination of the system specified by the user and the information indicating the operation specified by the user are not associated and stored in the memory, the computer requests a system to perform name resolution based on the information indicating the destination of the system specified by the user, accesses the system according to the address obtained in response to the request, and if the information indicating the destination of the system specified by the user and the information indicating the operation specified by the user are associated and stored in the memory, the computer does not request the system to perform name resolution based on the information indicating the address of the system specified by the user. [Effects of the Invention]
[0012] According to the inventions of claims 1 and 4, the increase in the load required for the decision can be suppressed compared to when an electronic certificate is used to determine whether to allow access, and unnecessary denial of access to the system being accessed can be prevented compared to when access is determined based only on information indicating the destination.
[0013] According to the invention of claim 2, it is possible to determine whether or not access to the system to be accessed is permitted for each user.
[0014] According to the invention of claim 3, when information indicating the destination of the system to be accessed, information indicating operations that are prohibited for the system to be accessed, and the address of the system to be accessed are linked and managed by the management system, the information managed by the management system can be updated in response to a request from the information processing system. [Brief explanation of the drawings]
[0015] [Figure 1] 1 is a block diagram illustrating an example of an overall system according to an embodiment. [Figure 2] FIG. 2 is a block diagram illustrating an example of hardware of the image forming apparatus according to the embodiment. [Figure 3] FIG. 10 is a diagram illustrating an example of a list of prohibited conditions. [Figure 4] FIG. 6 is a flowchart illustrating an example of processing performed by the image forming apparatus according to the embodiment. [Figure 5] FIG. 10 is a block diagram showing an example of an overall system according to a modified example. DETAILED DESCRIPTION OF THE INVENTION
[0016] An example of an overall system according to an embodiment will be described with reference to Fig. 1. Fig. 1 is a block diagram showing an example of an overall system according to an embodiment.
[0017] For example, the overall system according to the embodiment includes an image forming device 10, a DoH server 12, and servers 14A, . . . , 14N. Hereinafter, when it is not necessary to distinguish between the servers 14A, . . . , 14N, each of the servers 14A, . . . , 14N will be referred to as a "server 14." In the example shown in FIG. 1, multiple servers 14 are included in the overall system, but the number of servers 14 included in the overall system may be one. Also, multiple image forming devices 10 may be included in the overall system.
[0018] The image forming apparatus 10 is an example of an information processing system, and each server 14 is an example of an accessed system.
[0019] The image forming device 10, the DoH server 12, and the server 14 communicate with other devices via a communication path N. The communication path N is, for example, a network such as the Internet. The communication path N may also include a LAN (Local Area Network) or the like. Part or all of the communication path N may be established by wired communication, or may be established by wireless communication such as Wi-Fi (registered trademark).
[0020] The image forming apparatus 10 is a printer, scanner, copier, facsimile, or multifunction peripheral (e.g., a device having the functions of multiple devices such as a printer, scanner, and copier). The image forming apparatus 10 executes jobs such as print jobs, scan jobs, and copy jobs.
[0021] The image forming device 10 has at least one of the following functions: a function to download files such as document data and image data from the server 14; and a function to upload files to the server 14. For example, the image forming device 10 has a function to download files from the server 14 and print them, and a function to upload files generated by scanning documents to the server 14. In addition, the image forming device 10 may receive files from a terminal device such as a personal computer or a smartphone and print them, or may send files generated by scanning documents to the terminal device.
[0022] For example, examples of operations using the image forming apparatus 10 and the server 14 include an operation in which the image forming apparatus 10 downloads a file from the server 14 on the cloud and prints it, an operation in which the image forming apparatus 10 generates a file such as image data by scanning an original and transmits the file to the server 14 on the cloud, and an operation in which the image forming apparatus 10 transmits image data such as document data received by facsimile to the server 14 on the cloud. Of course, operations other than these may also be realized by the image forming apparatus 10 and the server 14.
[0023] The DoH server 12 is a server that performs name resolution via encrypted communication. In other words, the DoH server 12 is a server that converts between domain names and IP addresses. Specifically, the DoH server 12 converts domain names into IP addresses (i.e., raw lookup) and converts IP addresses into domain names (i.e., reverse lookup). DoH is an example of a method for performing name resolution via encrypted communication, but encrypted communication other than DoH may also be used.
[0024] The server 14 is an online storage such as a cloud storage, or a server that provides various online services and web applications.
[0025] The image forming apparatus 10 will be described below with reference to Fig. 2. Fig. 2 is a block diagram showing an example of hardware of the image forming apparatus 10.
[0026] The image forming device 10 includes an image forming unit 16, a UI 18, a communication device 20, a memory 22, and a processor 24.
[0027] The image forming unit 16 has at least one of the functions of printing, scanning, copying, and facsimile. The printing method and scanning method are not particularly limited. For example, electrophotography, inkjet, thermal, or thermal transfer may be used as the printing method.
[0028] The UI 18 is a user interface and includes a display and an operation device. The display is a liquid crystal display, an EL display, or the like. The operation device is a keyboard, a mouse, input keys, an operation panel, or the like. The UI 18 may be a touch panel UI that combines a display and an operation device. The UI 18 accepts operations from the user. Furthermore, the user may use the UI 18 to change the prohibition condition information, which will be described later.
[0029] The communication device 20 includes one or more communication interfaces having a communication chip, a communication circuit, etc., and has a function of transmitting data to other devices and a function of receiving data from other devices. The communication device 20 may have a wireless communication function or a wired communication function.
[0030] The memory 22 is a device that configures one or more storage areas for storing data. The memory 22 is, for example, a hard disk drive (HDD), a solid state drive (SSD), various types of memory (e.g., RAM, DRAM, NVRAM, ROM, etc.), other storage devices (e.g., optical disks, etc.), or a combination thereof.
[0031] Prohibition condition information is pre-stored in memory 22. The prohibition condition information is information for determining whether or not access from image forming apparatus 10 to each system is permitted, and is information indicating operations that are prohibited for the accessed system and users who are prohibited from performing those operations. As described above, server 14 is an example of a system here. In other words, the prohibition condition information is information for determining whether or not access from image forming apparatus 10 to each server 14 is permitted, and is information indicating operations that are prohibited for the accessed server 14 and users who are prohibited from performing those operations.
[0032] For example, for each server 14, information indicating the destination of the server 14 (hereinafter referred to as "destination information") and information indicating operations prohibited for the server 14 (hereinafter referred to as "prohibited operations") (hereinafter referred to as "prohibited operation information") are linked to each other in advance and included in the prohibited condition information.
[0033] For each server 14, destination information of the server 14, prohibited operation information indicating operations prohibited for that server 14, and information for identifying the user (hereinafter referred to as "prohibited user") who is prohibited from performing that operation (hereinafter referred to as "prohibited user information") may be linked to each other in advance and included in the prohibition condition information.
[0034] The destination information is, for example, a domain name such as an FQDN. The prohibited operations are, for example, transferring a file, posting a file, receiving a file, etc. The prohibited user information is, for example, information indicating an account linked to the prohibited user, information indicating the name of the prohibited user, a user ID linked to the prohibited user, or information indicating the attribute or type of the prohibited user.
[0035] When name resolution is performed, the processor 24 determines whether or not to permit access to a system (for example, the server 14) in accordance with the prohibition condition information.
[0036] When a user specifies a system to be accessed (e.g., a certain server 14) and an operation to be performed on the system, and the destination information of the system specified by the user and information indicating the operation specified by the user are not linked and included in the prohibition condition information, the processor 24 requests a system to perform name resolution (e.g., the DoH server 12) to perform name resolution based on the destination information of the system specified by the user. For example, the processor 24 transmits the destination information of the system specified by the user to the DoH server 12 and requests the DoH server 12 to perform name resolution based on the destination information. In response to the request, the DoH server 12 converts the destination information transmitted from the image forming device 10 into an IP address and transmits the IP address to the image forming device 10. The processor 24 accesses the system specified by the user according to the IP address acquired in response to the name resolution request.
[0037] When a user specifies a system to be accessed (e.g., a server 14) and an operation to be performed on that system, and the destination information of the system specified by the user and information indicating the operation specified by the user are linked and included in the prohibition condition information, the processor 24 does not request the system to perform name resolution (e.g., DoH server 12) to perform name resolution based on the address information of the system specified by the user.
[0038] In other words, if the operation specified by the user does not correspond to a prohibited operation for the system to be accessed specified by the user, the processor 24 requests the DoH server 12 to perform name resolution based on the destination information of the system specified by the user.
[0039] If the operation specified by the user corresponds to a prohibited operation for the system to be accessed specified by the user, the processor 24 does not request the DoH server 12 to perform name resolution based on the destination information of the system specified by the user.
[0040] The system to be accessed and the operation to be performed on that system are specified, for example, via the UI 18. That is, the user specifies the system to be accessed and the operation to be performed on that system by using the UI 18. As another example, the system to be accessed and the operation to be performed on that system may be specified via a terminal device (for example, a personal computer, a smartphone, etc.) connected to the image forming apparatus 10.
[0041] When the destination information, prohibited operation information, and prohibited user information are linked to each other in advance and included in the prohibition condition information, the processor 24 may execute the following process.
[0042] When a user specifies a system to be accessed (e.g., a server 14) and an operation to be performed on the system, if the destination information of the system specified by the user, the information indicating the operation specified by the user, and the information indicating the user are not linked and included in the prohibition condition information, the processor 24 requests a system to perform name resolution (e.g., the DoH server 12) to perform name resolution based on the destination information of the system specified by the user. The processor 24 accesses the system specified by the user according to the IP address acquired in response to the name resolution request.
[0043] The information indicating the user is, for example, information indicating an account associated with the user, information indicating the name of the user, or a user ID associated with the user. For example, when the user logs in to the image forming apparatus 10, the user inputs information indicating the user (for example, information indicating the account) to the image forming apparatus 10 via the UI 18. The information indicating the user may be input to the image forming apparatus 10 using an IC card, a smartphone, or another mobile terminal.
[0044] When a user specifies a system to be accessed (e.g., a server 14) and an operation to be performed on that system, if the destination information of the system specified by the user, information indicating the operation specified by the user, and information indicating the user are linked and included in the prohibition condition information, the processor 24 does not request the system to perform name resolution (e.g., DoH server 12) to perform name resolution based on the address information of the system specified by the user.
[0045] In other words, even if the operation specified by the user corresponds to a prohibited operation for the system to be accessed specified by the user, if the user does not correspond to a prohibited user for the system to be accessed specified by the user, the processor 24 requests the DoH server 12 to perform name resolution based on the destination information of the system to be accessed specified by the user. Also, even if the operation specified by the user does not correspond to a prohibited operation for the system to be accessed specified by the user, the processor 24 requests the DoH server 12 to perform name resolution based on the destination information of the system to be accessed specified by the user.
[0046] If the operation specified by the user corresponds to a prohibited operation for the system to be accessed specified by the user, and the user corresponds to a prohibited user for the system to be accessed specified by the user, the processor 24 does not request the DoH server 12 to perform name resolution based on the destination information of the system specified by the user.
[0047] In addition to the above-mentioned processes, the processor 24 controls the operations of each part of the image forming apparatus 10.
[0048] An example of the prohibition condition information will be described below with reference to Fig. 3. Fig. 3 is a diagram showing an example of a prohibition condition list. The prohibition condition list shown in Fig. 3 is an example of the prohibition condition information.
[0049] For example, in the prohibition conditions list, the domain name (e.g., FQDN) of server 14, the address (e.g., IP address) of server 14, information indicating prohibited operations on server 14, and information indicating prohibited users are linked to one another for each server 14. In the example shown in Fig. 3, the address (e.g., IP address) of server 14 is included in the prohibition conditions list, but the address of server 14 does not have to be included in the prohibition conditions list.
[0050] 3, file transfer, file posting, and file reception are included in the list of prohibited conditions as examples of prohibited operations. File transfer is an operation (e.g., uploading) of sending a file from the image forming apparatus 10 to the accessed server 14. File posting is an operation of posting a file to an online service or a Web application. File reception is an operation (e.g., downloading) of receiving a file from the accessed server 14 by the image forming apparatus 10.
[0051] In the example shown in FIG. 3, general users and all users are included in the prohibition conditions list as examples of prohibited users. A general user refers to an attribute or type of user. A prohibited operation linked to a general user is an operation that is prohibited from being performed by a user who has the attribute of a general user. As an example other than the example shown in FIG. 3, information indicating an individual user's account or user ID may be included in the prohibition conditions list as information indicating a prohibited user.
[0052] For example, for a server 14 having the FQDN "drive.aaa.com", the operation "file transfer" by a user with the attribute "general user" is prohibited. For a server 14 having the FQDN "abc.com", "all operations" by "all users" are prohibited. For a server 14 having the FQDN "XYZ", the operation "file posting" by a user with the attribute "general user" is prohibited. For a server 14 having the FQDN "aaa.com", the operation "file reception" is prohibited.
[0053] In the example shown in Fig. 3, an FQDN is used as the domain name, but each server 14 may be identified by a domain name other than an FQDN. Furthermore, the prohibited operations and prohibited users shown in Fig. 3 are merely examples, and prohibited operations other than those shown in Fig. 3 and prohibited users other than those shown in Fig. 3 may be included in the prohibition conditions list. Furthermore, the type of file (for example, a confidential document or a document permitted to be made public) may be included as a prohibition condition in the prohibition conditions list.
[0054] An example of processing by the image forming apparatus 10 will be described below with reference to Fig. 4. Fig. 4 is a flowchart showing the flow of this processing.
[0055] First, a user logs in to the image forming apparatus 10 by inputting his / her own user information (e.g., information indicating an account) into the image forming apparatus 10 using the UI 18 (S01). As a result, the image forming apparatus 10 identifies the user who has logged in to the image forming apparatus 10.
[0056] Next, the user selects an operation desired by the user using the UI 18 (S02). Here, as an example, an application is selected as the operation. When an application is selected by the user, the selected application is launched. Here, as an example, a scan application is selected. The scan application is an application that causes the image forming device 10 to scan a document to generate a file (e.g., document data or image data) and transmits the file to the server 14 to be accessed, and is an example of an operation.
[0057] Next, the user uses the UI 18 to select the server 14 to be accessed (S03). For example, the user selects the server 14 to which the file generated by scanning is to be sent. For example, a list of servers 14 is displayed on the display of the UI 18, and the user selects the server 14 to be sent from the list. The server 14 to be sent is an example of the server 14 to be accessed. As another example, the user may use the UI 18 to input the URL of the server 14 to be accessed into the image forming apparatus 10.
[0058] In step S03, if the server 14 to be accessed is selected by its IP address instead of its FQDN, the processor 24 checks whether the IP address is included in the list of prohibited conditions. For example, in step S03, if the user selects the server 14 to be accessed by inputting or specifying an IP address, the processor 24 checks whether the IP address is included in the list of prohibited conditions.
[0059] If the IP address entered or specified by the user is included in the list of prohibited conditions, the processor 24 prohibits access to the server 14 to which the IP address is assigned. In this case, the application selected by the user is not executed, and the process ends.
[0060] If the IP address input or specified by the user is not included in the prohibition conditions list (S04, No), a process of reverse-looking up the FQDN from the IP address is performed (S05). The processor 24 sends the IP address to the DoH server 12 and requests a reverse lookup from the DoH server 12. The DoH server 12 performs a reverse lookup from the IP address to the FQDN and sends the FQDN to the image forming device 10. In this way, the image forming device 10 obtains the FQDN of the server 14 to be accessed. Then, the process proceeds to step S06.
[0061] If the server 14 to be accessed is selected by the FQDN in step S03 (S04, Yes), or if the FQDN is obtained by reverse lookup, the processor 24 checks whether the FQDN is included in the prohibited conditions list (S06).
[0062] If the FQDN is not included in the prohibition condition list (S07, No), the process proceeds to step S13. In step S13, the processor 24 requests name resolution from the DoH server 12. The process of step S13 will be described in detail later.
[0063] If the FQDN is included in the prohibition conditions list (S07, Yes), the processor 24 determines whether the operation selected by the user is included in the prohibition conditions list (S08). More specifically, the processor 24 checks whether the FQDN and the operation selected by the user are associated and included in the prohibition conditions list. In other words, the processor 24 checks whether the operation selected by the user is prohibited for the server 14 having the FQDN. In the example described above, the processor 24 checks whether the FQDN and the scan application selected by the user are associated and included in the prohibition conditions list.
[0064] If the FQDN and the operation selected by the user (for example, a scan application) are not associated with each other and are not included in the prohibition condition list (S09, No), the process proceeds to step S13.
[0065] If the FQDN and the operation selected by the user (e.g., a scan application) are associated and included in the prohibited conditions list (S09, Yes), the processor 24 checks whether the user who logged in to the image forming device 10 is included in the prohibited conditions list (S10). That is, the processor 24 checks whether the user is associated with the FQDN and the operation as a prohibited user.
[0066] If the user is not included in the prohibition condition list as a prohibited user linked to the FQDN and operation (S11, No), the process proceeds to step S13.
[0067] If the user is included in the prohibition condition list as a prohibited user linked to the FQDN and operation (S11, Yes), the processor 24 does not request name resolution from the DoH server 12 (S12). In other words, the processor 24 does not request name resolution from the DoH server 12 to convert the FQDN of the server 14 specified by the user into an IP address. In this case, the operation selected by the user (e.g., a scan application) is not executed, and the process ends.
[0068] In step S13, the processor 24 transmits the FQDN of the server 14 specified by the user to the DoH server 12 and requests the DoH server 12 to perform name resolution to convert the FQDN into an IP address. Upon receiving the request, the DoH server 12 converts the FQDN transmitted from the image forming device 10 into an IP address and transmits the IP address to the image forming device 10. In this way, the processor 24 obtains the IP address corresponding to the FQDN of the server 14 specified by the user.
[0069] When the processor 24 acquires the IP address from the DoH server 12, it accesses the server 14 to which the IP address is assigned in accordance with the IP address (S14). When a file such as image data is generated in the image forming device 10 by executing the scan application, the processor 24 transmits (e.g., uploads) the generated file to the server 14 to which the IP address is assigned. In this way, the operation selected by the user is executed.
[0070] According to this embodiment, there is no need to use an electronic certificate to determine whether or not to allow access to the server 14, so the increase in the load required for the determination can be suppressed compared to when an electronic certificate is used to determine whether or not to allow access.
[0071] Furthermore, because access permission is determined using not only destination information but also operation prohibition information, it is possible to prevent unnecessary prohibition of access to the destination server 14, compared to when access permission is determined using destination information alone. In other words, if access permission to server 14 is determined using destination information alone, access to server 14 may be prohibited even when an operation that is not prohibited on server 14 is performed. According to this embodiment, when a user specifies an operation that is not prohibited on server 14, access to server 14 may be permitted, thereby preventing unnecessary access prohibition.
[0072] (Variation) A modified example will be described with reference to Fig. 5. Fig. 5 is a diagram showing an example of an overall system according to the modified example. The overall system according to the modified example includes a management system 26. The configuration other than the management system 26 is the same as the configuration shown in Fig. 1.
[0073] The management system 26 manages the prohibition condition list and provides the prohibition condition list to the image forming apparatus 10. When multiple image forming apparatuses 10 are connected to the management system 26 via the communication path N, the management system 26 provides the prohibition condition list to each image forming apparatus 10. For example, the management system 26 includes a processor and a memory. The processor of the management system 26 provides the prohibition condition list to each image forming apparatus 10.
[0074] For example, for each server 14, the destination information of the server 14, operation prohibition information indicating operations prohibited for the server 14, and the address (e.g., IP address) of the server 14 are linked to each other, stored in the memory of the management system 26, and managed by the management system 26.
[0075] For each server, destination information of the server 14, operation prohibition information indicating operations prohibited for the server 14, the address (e.g., IP address) of the server 14, and prohibited user information of users prohibited from performing the operations (i.e., prohibited users) may be associated with one another and stored in the memory of the management system 26, and managed by the management system 26. For example, the prohibition condition list shown in FIG. 3 may be stored in the memory of the management system 26 and managed by the management system 26. In other words, for each server 14, the FQDN of the server 14, the IP address of the server 14, prohibited operation information indicating operations prohibited for the server 14, and prohibited user information indicating prohibited users prohibited from performing the operations may be associated with one another and stored in the memory of the management system 26, and managed by the management system 26.
[0076] The processor 24 of the image forming apparatus 10 acquires the prohibition conditions list from the management system 26 via the communication path N and stores it in the memory 22 of the image forming apparatus 10. For example, the image forming apparatus 10 is set to acquire the prohibition conditions list from the management system 26. The processor 24 acquires the prohibition conditions list from the management system 26 in accordance with the setting.
[0077] For example, the processor 24 accesses the management system 26 at a predetermined timing or at a timing specified by the user, acquires the list of prohibited conditions from the management system 26, and stores the list of prohibited conditions in the memory 22. The processor 24 determines whether to permit the name resolution request in accordance with the list of prohibited conditions stored in the memory 22.
[0078] For example, the timing is the start-up of the image forming apparatus 10. In this case, when the image forming apparatus 10 is powered on and starts up, the processor 24 accesses the management system 26 to obtain the prohibition conditions list from the management system 26 and stores the prohibition conditions list in the memory 22.
[0079] The time of startup is one example of the timing, and the processor 24 may obtain the prohibition conditions list from the management system 26 at a timing other than the time of startup. For example, the processor 24 may obtain the prohibition conditions list from the management system 26 at a timing specified by the user after the image forming apparatus 10 has started up. As another example, the processor 24 may obtain the prohibition conditions list from the management system 26 at predetermined time intervals (for example, every 10 minutes, every hour, or every day). These settings may be changed by an administrator or a user.
[0080] When a condition included in the prohibition condition list is changed, the prohibition condition list stored in the management system 26 is changed. For example, when a condition included in the prohibition condition list is changed, the administrator changes the prohibition condition list stored in the management system 26. In this way, the prohibition condition list stored in the memory 22 of the image forming apparatus 10 is updated without the administrator or user having to manually change the prohibition condition list stored in the memory 22 of the image forming apparatus 10. For example, when multiple image forming apparatuses 10 are included in an overall system, each of the multiple image forming apparatuses 10 obtains a prohibition condition list from the management system 26, and the prohibition condition list stored in each image forming apparatus 10 is updated without the administrator or user having to change the prohibition condition list individually at each image forming apparatus 10. Of course, the prohibition condition list may be set individually for each image forming apparatus 10 without obtaining the prohibition condition list from the management system 26.
[0081] In addition, in a modified example, if the IP address included in the prohibition conditions list stored in memory 22 and associated with the destination information (e.g., FQDN) of server 14 specified by the user differs from the IP address acquired by image forming device 10 through name resolution by DoH server 12 based on the destination information (e.g., FQDN) of server 14 specified by the user, processor 24 requests management system 26 to change the prohibition conditions list stored in management system 26. In other words, if the IP address stored in memory 22 for the destination information (e.g., FQDN) of server 14 specified by the user differs from the IP address acquired through name resolution by DoH server 12, processor 24 requests management system 26 to change the prohibition conditions list stored in management system 26.
[0082] In other words, when name resolution is performed by the DoH server 12, if the IP address included in the prohibition conditions list stored in memory 22 for the destination information (e.g., FQDN) of the server 14 specified by the user differs from the IP address obtained from the DoH server 12, the processor 24 determines that the prohibition conditions list is out of date.
[0083] For example, if the IP address of a certain server 14 is changed, the IP address of that server 14 registered in the DoH server 12 is changed, but the IP address of that server 14 included in the prohibition conditions list stored in the management system 26 may not be changed. In this case, even if the destination information is the same server 14, the IP address included in the prohibition conditions list stored in memory 22 may differ from the IP address obtained from the DoH server 12. In this case, the processor 24 requests the management system 26 to change the prohibition conditions list.
[0084] For example, the processor 24 requests the management system 26 to change the list of prohibited conditions by transmitting request information indicating a request to change the list of prohibited conditions to the management system 26.
[0085] When the processor of the management system 26 receives request information from the image forming device 10, it checks whether there is a difference between the destination information and IP address included in the prohibition conditions list stored in the management system 26 and the destination information and IP address stored in the DoH server 12.
[0086] For example, the processor of the management system 26 obtains the destination information (e.g., FQDN) and IP address of each server 14 from the DoH server 12, compares the destination information and IP address contained in the prohibition conditions list stored in the management system 26 with the destination information and IP address obtained from the DoH server 12, and checks whether there are any differences between them.
[0087] If there is a difference, the processor of the management system 26 updates the prohibition conditions list by changing the destination information and IP address included in the prohibition conditions list stored in the management system 26 to the destination information and IP address acquired from the DoH server 12. If there is no difference, the processor of the management system 26 does not update the prohibition conditions list stored in the management system 26.
[0088] The processor 24 of the image forming apparatus 10 acquires the prohibition condition list from the management system 26 at a predetermined timing, and updates the prohibition condition list stored in the memory 22 of the image forming apparatus 10.
[0089] Some of the functions of the image forming apparatus 10 may be realized by a device other than the image forming apparatus 10. When some of the functions of the image forming apparatus 10 are realized by a device other than the image forming apparatus 10, the image forming apparatus 10 and the other device may constitute an information processing system. In other words, the functions of the image forming apparatus 10 may be realized by a single device, or may be realized by an information processing system including multiple devices. The same applies to the DoH server 12, the server 14, and the management system 26.
[0090] Each function of the image forming apparatus 10 is realized, for example, by cooperation between hardware and software. For example, each function of the image forming apparatus 10 is realized by the processor 24 of the image forming apparatus 10 reading and executing a program stored in memory. The program is stored in memory via a recording medium such as a CD or DVD, or via a communication path such as a network. Similarly, each function of the image forming apparatus 10 is realized by the processor 24 of the image forming apparatus 10 reading and executing a program stored in memory. The program is stored in memory via a recording medium such as a CD or DVD, or via a communication path such as a network.
[0091] In the above-described embodiment and modified examples, the image forming apparatus 10 has been described, but the embodiment and modified examples may be applied to an apparatus other than the image forming apparatus 10. For example, the above-described embodiment and modified examples may be applied when a personal computer or a smartphone accesses the server 14 to upload a file to the server 14 or download a file from the server 14. The above-described embodiment and modified examples may also be applied when a proxy server is used.
[0092] In the above embodiments, the term "processor" refers to a processor in a broad sense, and includes general-purpose processors (e.g., CPU: Central Processing Unit, etc.) and dedicated processors (e.g., GPU: Graphics Processing Unit, ASIC: Application Specific Integrated Circuit, FPGA: Field Programmable Gate Array, programmable logic device, etc.). Furthermore, the operations of the processor in the above embodiments may not only be performed by a single processor, but may also be performed by multiple processors located in physically separate locations working together. Furthermore, the order of the operations of the processor is not limited to the order described in the above embodiments, and may be changed as appropriate.
[0093] (Addendum) (((1))) a processor and a memory, The memory includes: storing information indicating the destination of the system to be accessed and information indicating the prohibited operation on the system to be accessed in association with each other; The processor: When a system to be accessed and an operation to be performed on that system are designated by a user, if information indicating the destination of the system designated by the user and information indicating the operation designated by the user are not associated and stored in the memory, a name resolution is requested from a system that performs name resolution based on the information indicating the destination of the system designated by the user, and the system is accessed according to the address obtained in response to the request; When information indicating the destination of the system designated by the user and information indicating the operation designated by the user are associated and stored in the memory, the system that performs name resolution is not requested to perform name resolution based on the information indicating the destination of the system designated by the user. Information processing system. (((2))) The memory further comprises: storing information indicating the destination of the system to be accessed, information indicating an operation prohibited for the system to be accessed, and information indicating a user who is prohibited from performing the operation in association with each other; The processor: If the information indicating the destination of the system designated by the user, the information indicating the operation designated by the user, and the information indicating the user are not stored in association with each other in the memory, a name resolution system is requested to perform name resolution based on the information indicating the destination of the system designated by the user, and the system is accessed according to the address obtained in response to the request; When information indicating the destination of the system designated by the user, information indicating the operation designated by the user, and information indicating the user are associated and stored in the memory, the system that performs name resolution is not requested to perform name resolution based on the information indicating the destination of the system designated by the user. The information processing system according to (((1))). (((3))) information indicating the destination of a system to be accessed, information indicating operations prohibited for the system to be accessed, and an address of the system to be accessed are associated with each other and managed by a management system; The processor further comprises: information indicating the destination of the system to be accessed, information indicating operations prohibited for the system to be accessed, and an address of the system to be accessed, which are all linked to each other, are acquired from the management system and stored in the memory; The processor further comprises: If the address stored in the memory in association with the information indicating the destination of the system designated by the user is different from the address acquired by name resolution based on the information indicating the destination of the system designated by the user, a request is made to the management system to change the association between the information indicating the destination of the system to be accessed, the information indicating operations prohibited for the system to be accessed, and the address of the system to be accessed. The information processing system according to (((1))). (((4))) a computer having a memory for storing information indicating a destination of a system to be accessed and information indicating a prohibited operation on the system to be accessed in association with each other, When a system to be accessed and an operation to be performed on that system are designated by a user, if information indicating the destination of the system designated by the user and information indicating the operation designated by the user are not associated and stored in the memory, a name resolution is requested from a system that performs name resolution based on the information indicating the destination of the system designated by the user, and the system is accessed according to the address obtained in response to the request; When information indicating the destination of the system designated by the user and information indicating the operation designated by the user are associated and stored in the memory, the system that performs name resolution is not requested to perform name resolution based on the information indicating the destination of the system designated by the user. A program that works like this. The information processing system according to (((1))) or the program according to (((4))) can reduce the load required for making a decision compared to when an electronic certificate is used to determine whether or not to allow access, and can prevent unnecessary denial of access to the system being accessed compared to when an access is determined based only on information indicating the destination. According to the information processing system of (((2))), it is possible to determine whether or not access to the system to be accessed is permitted for each user. According to the information processing system of (((3))), when information indicating the destination of the system to be accessed, information indicating operations that are prohibited on the system to be accessed, and the address of the system to be accessed are linked and managed by the management system, the information managed by the management system can be updated in response to a request from the information processing system. [Explanation of symbols]
[0094] 10 image forming device, 12 DoH server, 14A, 14N servers, 22 memory, 24 processor, 26 management system
Claims
1. a processor and a memory, The memory includes: storing information indicating the destination of the system to be accessed and information indicating the prohibited operation on the system to be accessed in association with each other; The processor: When a system to be accessed and an operation to be performed on that system are designated by a user, if information indicating the destination of the system designated by the user and information indicating the operation designated by the user are not associated and stored in the memory, a name resolution is requested from a system that performs name resolution based on the information indicating the destination of the system designated by the user, and the system is accessed according to the address obtained in response to the request; When information indicating the destination of the system designated by the user and information indicating the operation designated by the user are associated and stored in the memory, the system that performs name resolution is not requested to perform name resolution based on the information indicating the destination of the system designated by the user. Information processing system.
2. The memory further comprises: storing information indicating the destination of the system to be accessed, information indicating an operation prohibited for the system to be accessed, and information indicating a user who is prohibited from performing the operation in association with each other; The processor: If the information indicating the destination of the system designated by the user, the information indicating the operation designated by the user, and the information indicating the user are not stored in association with each other in the memory, a name resolution system is requested to perform name resolution based on the information indicating the destination of the system designated by the user, and the system is accessed according to the address obtained in response to the request; When information indicating the destination of the system designated by the user, information indicating the operation designated by the user, and information indicating the user are associated and stored in the memory, the system that performs name resolution is not requested to perform name resolution based on the information indicating the destination of the system designated by the user. The information processing system according to claim 1 .
3. information indicating the destination of a system to be accessed, information indicating operations prohibited for the system to be accessed, and an address of the system to be accessed are associated with each other and managed by a management system; The processor further comprises: information indicating the destination of the system to be accessed, information indicating operations prohibited for the system to be accessed, and an address of the system to be accessed, which are all linked to each other, are acquired from the management system and stored in the memory; The processor further comprises: If the address stored in the memory in association with the information indicating the destination of the system designated by the user is different from the address acquired by name resolution based on the information indicating the destination of the system designated by the user, a request is made to the management system to change the association between the information indicating the destination of the system to be accessed, the information indicating operations prohibited for the system to be accessed, and the address of the system to be accessed. The information processing system according to claim 1 .
4. a computer having a memory for storing information indicating a destination of a system to be accessed and information indicating a prohibited operation on the system to be accessed in association with each other, When a system to be accessed and an operation to be performed on that system are designated by a user, if information indicating the destination of the system designated by the user and information indicating the operation designated by the user are not associated and stored in the memory, a name resolution is requested from a system that performs name resolution based on the information indicating the destination of the system designated by the user, and the system is accessed according to the address obtained in response to the request; When information indicating the destination of the system designated by the user and information indicating the operation designated by the user are associated and stored in the memory, the system that performs name resolution is not requested to perform name resolution based on the information indicating the destination of the system designated by the user. A program that works like this.
Citation Information
Patent Citations
Using DNS communication to filter domain names
JP2014519751A
Packet filtering device
JP2017135622A